Shared Security Podcast

A new LG monitor triggering an automatic Windows companion app with a McAfee ad is more than an annoying popup. It is a reminder that hardware setup has become a software supply chain, and users often do not get meaningful control over what vendor utilities, ads, telemetry, and startup apps arrive when they connect a device.

Show Notes

You plug in a new monitor. Windows detects the hardware, pulls down a vendor companion app, and the first thing you see is… a McAfee ad. That’s the story that kicks off this episode, but the bigger issue is not just one annoying popup.

Hardware setup has become a software delivery channel. Drivers, companion apps, RGB utilities, printer suites, vendor dashboards, trialware, telemetry, ads, and startup apps can all arrive through a process most users think of as “just making the device work.” Tom, Scott, and Kevin discuss where convenience turns into bloatware, why user consent matters, and how these trusted installation paths could be abused for worse than advertising.

The discussion also covers a related Krebs on Security story about LG smart TV apps that allowed televisions to be used as residential proxy nodes. If monitors, TVs, printers, keyboards, and other peripherals are really networked software platforms, then consumers need to treat them more like endpoints and less like harmless appliances.

Practical advice: check what gets installed after connecting new hardware, review Windows Startup Apps, uninstall vendor utilities you do not need, dig through smart-TV privacy and ad settings, and segment smart devices away from the computers and phones you use for sensitive work.

** Links mentioned on the show **

Tom’s Hardware: Companies are now using automatic Windows installers to display adware through the Microsoft Store when you install new hardware https://www.tomshardware.com/software/windows/companies-are-now-using-automatic-windows-installers-to-display-adware-through-the-microsoft-store-when-you-install-new-hardware-customer-immediately-gets-mcafee-ads-on-their-pc-after-connecting-new-lg-monitor-heres-how-to-block-the-new-ads

Krebs on Security: LG to Ban Residential Proxies from Smart TV Apps https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/

Hackread: LG monitors installing adware-like app on Windows PCs https://hackread.com/lg-monitors-install-adware-app-windows-pcs/

** Watch this episode on YouTube **

https://youtu.be/E-lsZbkbmI8

** Become a Shared Security Supporter **

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

** Thank you to our sponsors! **

SLNT

Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

** Subscribe and follow the podcast **

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

What is Shared Security Podcast?

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Welcome to the Shared Security Podcast, the longest running cybersecurity and privacy show

for actual humans.

No jargon, no hype, just honest analysis from industry veterans who've seen everything

and survived it.

Each week we break down the stories that matter, expose the nonsense that doesn't, and give

you the tools to stay safe in a world where everything is connected and nothing

is guaranteed.

This is Shared Security.

Today on Shared Security we're talking about something that sounds like a punchline but

is actually a pretty good example of where consumer tech, security and privacy all collide.

You plug in a new monitor, Windows automatically pulls down a vendor companion app, and the

first thing you see is one of those damn Mac fjads.

Man, can't get rid of them, right?

Well, this sounds like an annoying bloatware story, but underneath is a bigger question.

Who gets to put software on your computer just because you connected a piece of hardware?

Drivers and companion apps can be useful, but when that trusted setup path becomes

an advertising channel, users lose visibility and control.

So we'll be talking about that, and we'll also touch on a related Brian Krebs story

that Scott happened to send over about LG Smart TV apps being used as residential proxy nodes.

So what the hell is going on here with LG, right?

Well joining me to explain everything in full detail are my two co-hosts, Scott Wright

and Kevin Tackett.

Everyone's back.

Look at this.

This is my front.

Oh, the front.

Yes.

Yeah.

So confusing.

We don't want to see the back.

No, no, you don't want to see the front.

I just want to point out that we're going to make fun of LG quite a bit here.

We will.

But the reality is I don't know of a quote unquote smart television

that doesn't fall into this.

This category of really thanks.

It's true.

I actually just bought last weekend a I&Ear television,

which I even said to the guy at Best Buy, like I thought Pioneer was just radios in your

car.

Yeah, I've never heard of a Pioneer TV.

That's interesting.

Neither have I.

And it was a good price and it's it's Roku based.

OK.

Yeah.

And I'm not and I want to be very clear for those listening, not a sponsor, not

recommending.

So it's not that they're bad.

I just I have no recommendation.

It's a TV that sits there.

You turn it on videos play.

And hopefully it doesn't take more than you wanted to.

Yeah, yeah.

The stuff that's built into these televisions, I recently had to buy a

small television for another reason.

I I feel as I've recently bought a lot of TVs.

But let's ignore that.

And I and I this is the small television was just a

I need a machine right there so we can hook the Nintendo Switch to it

and not worry about it and have a way to play in my office.

When the Walmart picked up the cheapest television they had that fit

the size I wanted and ran home real quick and plugged it in,

turned it on, and it immediately said to use this television.

You need a Walmart dot com account.

And I'm like, I need a what all smart TVs have this issue.

LG seems to be the one that we're going to make fun of right now.

Right.

I do think the idea of being able to proxy traffic through random

people's television seems like a bad plan.

I mean, as a pentester, I think it's pretty cool.

But no, no, not as a pentester as a pentester.

OK, let me ask you, Tom, you negotiating that in scope IP addresses

with your client. True.

Them televisions scattered around Orange Park.

I'm just saying my clients TVs. That's what I was looking at.

In that case, no.

Start out, start out, start out.

stars and scope. Hey, yeah, it's fine. It's fine. This is the risk that most people don't

think about. But the minute you have a device, television, phone, whatever, that you allow

basically anybody with a development account to publish an app that then gets downloaded

to your embedded device, TV, whatever, you run the risk of a malicious person

pushing something down. And it doesn't even have to be a malicious person building

the app. Yeah, the person building the app might have a stub intentions and have

this idea like, hey, I have a great thought about how this can work. And

then all of a sudden, some jerk like Tom comes up with a way to proxy

traffic through it, right? The ecosystem, I don't know if that's the

right word. But the ecosystem around embedded systems. So, you know, like the

supported apps, the third party ecosystem is just scary as heck, if you're worried

about privacy and security. And we hear all the time, well, Apple vets things,

Google vets things, I'm like, really? You know, yeah, they do. But they even

say we're only going to take it to here. We're not gonna stuff this

and the bad guys are always looking for ways to weaponize that stuff. And this

is a recurring theme that we've had on the on the show for maybe over a decade.

Yeah, the dolls that you know, you could, you know, program to record a saying

and it would speak, you know, in content. I'm still not allowed to discuss

those dolls. Yeah, you're banned. Kids dolls, I'm talking about. Okay.

Though I know you're talking about the kids dolls contractually, I'm

not allowed to talk about those dolls. Right? Yeah, so weaponization of

these devices that are, as you say, embedded, not as visible. And I have

a question for you guys just about the context of the first part of this

episode where we're talking about the ability to put in apps in the app

store that end up on the it's not clear to me if that ad for the Mac

if you add, is that popping up as a result of the processor in the monitor? Or

is that something that is triggered in the computer? So how I read it is that

as soon as you plug in a LG monitor, it goes automatically like windows will

detect that this is an LG monitor and it goes out to the windows

computer or acting. Yes. Okay. Yes. To pull down basically the driver

package, but it's like an app store package. Yeah. And what I've what and

how this this plays out is, it basically serves you this ad, essentially

saying, Hey, install this McAfee thing, right? Antivirus like the typical

thing you see. But it's triggered by you purchasing this monitor. The

thing that I think is is key thing that many people don't talk about very

often is that modern accessories or you know, peripherals, I think is the

right word for your computer back in the day, right? You would buy a sound

blaster and you'd flip some dip switches and you'd plug it in and you'd put

the disk get in the floppy disk ad and you install the drivers and you

might install some some software that came with it as well, whatever. And

that was the process. And I mean, it was a process that was

complicated enough for for many people that there was an entire market. I

made money doing that for people. And and then we got to the point where the

computer would detect the new peripheral and go out to the internet and

pull down the drivers. And over the last, I don't know how long, let's

say decade, maybe less than that, maybe more than that. But instead of

pulling down drivers, it pulls down an entire suite of applications that

includes the drivers. I'll pick on I just I just got a new laptop. I had a I

had a hardware issue with my laptop. We tried rebuilding it fixing it. Finally,

I got a new laptop. And the laptop I got is Lenovo. And nothing about

Lenovo. This isn't a complaint about them or anybody else. And but my

keyboard is a razor keyboard. Okay, I like the clickiest nest and

that's what I got. laptop plug it in, do all the reboots, get all the

drivers, everything else installed. I plug in the keyboard. And

immediately. Yep, it is pulling down not just keyboard drivers to

control it, but a collection of tools, cortex synapse. I don't even

know the other names, right? Now, a big part of them, they're

there to control the lights on my keyboard, because I want a rainbow

of colors to take all through on my keyboard constantly. You

didn't have a choice about pulling that stuff down. It just

came down. And my read of this LG articles, that's what

happened. It wasn't a set of drivers. It was a suite of

applications that included the drivers. And one of the things it

did was prompt you to install McAfee. Now, I will point out

because unlike some people, I won't name any names. I have zero

problems pointing out that McAfee has decades of working

with partners to embed the McAfee install, you went to

Best Buy, and you bought anything and you got handed a CD

ROM that had McAfee in it. For a while there, I don't know if

it's still this way. For a while there, if you downloaded the

Java runtime environment and installed it, there was a check

box to install McAfee. I think Adobe had the same thing. You

can get PDF reader and McAfee. And I want to point out, and

I will say this for the record, because we're recording

it, I do not believe there's been any time in my life that

I have ever thought to myself or recommended to anybody else,

you should run McAfee.

Yeah, never.

Which is why they as a company are forced similar to cold

collars and spammers, they are forced to get other people to

sneak it in, right? Because nobody in their right mind

would install this software directly. Just my opinion.

Yeah. And what's even more sad is John McAfee, the founder of

McAfee, may he rest in peace by the way, he is dead. But John

McAfee had nothing to do with the company after he sold it.

This was for what, years and decades, and he would even

post videos getting mad at McAfee for exactly what you

said, Kevin. And it's his own name in the company.

Mobile apps are just part of everyday life now. Banking,

healthcare, shopping, entertainment, you name it. And

with that comes a lot of trust, because users are putting

their personal data directly into your app. But here's the

reality. Mobile apps are a growing target. A recent

survey found that 72% of organizations experienced a

mobile app security incident last year. And 92% say

threats are only increasing. And the way attackers are

going after apps is pretty sophisticated. They're reverse

engineering them, modifying them and redistributing fake

versions through phishing campaigns, side loading, and

even third party app stores. So from a user's perspective,

everything can look completely legitimate. That's why

taking a proactive approach to mobile app security really

matters. You want to stay ahead of these threats, not

react after the damage is done. This is where Guard

Square comes in. They provide advanced protection for

both Android and iOS apps, along with automated security

testing to catch vulnerabilities early and real time

threat monitoring so you can actually see what's

happening out there. If your mobile app is critical to

your business, and it probably is, this is

something worth paying attention to. You can learn

more at GuardSquare.com. That's GuardSquare.com.

I think another example of that is printers,

right? Every time you get an HP printer or

whatever, it installs a whole bunch of stuff off either

off the, used to be the DVD, but now it's probably

doing the same thing, grabbing as much as it can

from the support site to run on your computer. So

yeah, that's one aspect of what we're talking about

here is the unauthorized installation, call it, of

AdWare or potentially worse stuff. But yeah, the

other story from Brian Krebs was around the

discovery that through a, I guess it's through an

app store of some kind of WebOS app store, I think.

Built into LG TVs, yeah. Yeah. I think it's just

LG TVs. I don't know if there's anything else, but

so people are finding ways to install, essentially

what ends up being a household proxy that you

don't know about. And in this case, again, I

don't know, I suspect it's the TV, right?

Well, what's interesting is these are actually

built into the apps as a way to get rid of ads. So

like in the article, they had an example of the

Pac-Man application, which is the game, it's

Pac-Man. And they literally say in a disclaimer,

if you want to get rid of ads, click here to

allow your TV to become a residential proxy.

Like they actually state it. Like, and so

what do people do? They're like, Oh, I want to

get rid of ads. Click the box. I just want to

play Pac-Man. And what's interesting to me is

like, the article doesn't explain like, what is

the purpose of the residential proxy? Meaning

What is the residential proxy?

I mean, I was just bowing porn.

I mean, I'm assuming it means that you're

allowing your TV to, maybe it's kind of like

that Amazon sidewalk feature where like it

spreads the network out so like your neighbors

can get, you know, better access. I'm not

really sure, but it just is bad. I wouldn't

say no, do not do this.

They're probably good and bad use cases, but

it's easier to imagine the bad ones.

Yeah. I mean, this this reminds me it's a

different name, whatever, but it reminds

me of like, you know, what was it?

World's a Warcraft used tour?

Yes. Yes. Right. Like, like you wow

client was actually sharing the client with

other people to to reduce.

I think it was World of Warcraft, right?

That was doing that. And but that was a

we understood it. Well, OK, we understood

it. I don't know that everybody did, right?

Like, that was something you accepted.

Like, yeah, OK, no problem.

I, you know, it was like companies

leveraging the BitTorrent system to

lower their own network costs.

Right. Right. Yeah.

Or imagine this is the same.

Yeah, SETI at home.

Remember the screensavers that you could

download to help find alien, you know, UFO

signals in space or the cure for cancer one.

Right. Yeah. Like, yeah.

Right. Wasn't it wasn't it us that discussed

the the SETI at home that was designed

around hacking Russian systems

to start the Ukrainian war?

Long time ago. Yeah.

Yeah. Yeah. Some time ago.

Yes. So so I was going to ask

like, do we have any tips or guidance

around anybody who has, you know, an LGTB

that might be hit them with a hammer?

Yeah, destroy them with fire.

Yeah. All seriousness.

I mean, we can talk about things,

but it's the same in my opinion.

And Tom, correct me if you disagree.

But in my opinion, this is the same

advice we're going to give with any other system.

Think about what you want to use it for.

Think about what you want to install on it.

Be reasonable and accept and understand

the risk you're opening yourself up to is that you're.

So like what I would recommend for most people

and we've recommended this before is that

evaluate how your network works, right?

Like you have a wireless network, right?

And check to see if if your network solution,

whether it's your TP-Link or your, you know, whatever.

I don't care.

Do they have some way to segment

things like smart TVs and stuff like that

away from your laptops and your devices that you care about?

Because I'm not doing online banking on my LGTB period, right?

But I am doing online banking on my laptop.

So I've segmented those two things

that they can't talk to each other to the best of your ability.

And that would be something within your network

system for less.

That's the best I can give you

because you don't have a lot of control over what the TV does.

Right. So I do have a question then.

So for less technical people who find themselves owning a TV

that happens to be, you know, affected or vulnerable.

First of all, will the TV work without you logging in or giving it any access?

It depends. I'm not anymore. Yeah, it depends.

Most likely a lot of these TVs know

like you can't use Netflix.

You can't use the apps until you agree to their policies.

You have to click through terms of service.

I mean, it's getting worse.

I can tell you that because every TV I've bought over the last several years

has gotten more invasive and there's to get out of those policies

and to like turn off like ads and all those things.

They're buried in the system settings.

And that I think that's one of my recommendations.

I was going to say people that are less technical is

you just got to go into your TV and you have to dig through the settings

and turn those things off. Yeah. Right.

Unless and some just kind of force you into you have to agree to these policies.

Otherwise, you just your TV becomes a dumb TV and you can't do anything.

Not even or won't even be a dumb TV, right?

Right. Like that that I think it was a TCL

television that I bought that works wire to wall.

I could not get past that screen without signing into Walmart.

I couldn't that could not figure out a way to just say no.

Right. Let me let me because all I was doing,

all I wanted was a display for the Nintendo Switch.

I don't have any hair.

You couldn't even plug in like a video out terminal into it and have a display.

The screen can log into this account.

I don't have a wall at the time.

I didn't have a Walmart.com account now.

So for the less technical people, the other thing I would say is one,

every less technical person I know has a computer friend.

Talk to your computer friend about your network.

If you can't do that, if you just hate people and people hate you,

me and you have to do something in your less technical,

a way to do segmentation

is to actually buy a different wireless device.

So let's say that you have a TP link device attached to your fiber connection.

Right. You can buy another different wireless device,

plug it into the device you have plugged into your

fiber, your cable, whatever and configure that as a completely different SSID

for an access point basically. Yeah. Yeah.

Right. So you would.

So now you literally have two wireless networks

and they would treat each other as external to each other.

Right. I think I said that right.

That is a I won't say it's a cheap way to do this.

It is the one of the less technical way to do it. Right.

You just and then you have two networks.

You connect to that one for your embedded stuff.

You connect to this one for your laptops,

your computers and your tablets that you care about using securely.

And then you just go that route that I don't like that answer.

But that is an answer.

If if either your network equipment doesn't support segmentation,

it's sometimes called guest networking or whatever.

If it doesn't support it or if you just don't know how to do it.

And I'll give you an example.

A lot of the less technical people,

they'll sign up for something like AT&T fiber and AT&T fiber will give them

a wireless access point that AT&T configures and manages and stuff like that.

They may I don't know what access they have,

but they may not have access to do the segmentation

and they would have to do this second option.

It's the best answer I've got. Sorry.

Yeah, or just go to like a thrift shop or something and find one of those old

CRT TVs, you know, tube TVs, which does not have ads because it's

that's literally the definition of a dumb TV.

And in fact, I mean, as somebody who sells and collects retro gaming

video games consoles, I have literally like three or four CRTs sitting around.

And I have seriously considered like plugging that back in

because I am so annoyed at these modern TVs.

And honestly, I think it's a great business idea for some company

to come out and sell a dumb like LCD

flat screen TV with no with nothing like like a monitor.

It's just a computer monitor, essentially, but it's 86 inches.

What if you could do an OEM deal, use the ones,

the cheapest ones are on the market and then put some kind of hardware

or software around the core of it to protect it from.

Oh, doing any weird stuff.

That'd be there. You have it.

Yeah, contact Scott to there we go for a new startup in Canada.

Proxy TV, something or another. Yes.

Yeah, I like it. I like it.

All right, everyone.

Well, I think that's all we have time for today.

Great topic and for anybody that has comments about this topic,

if you have ideas of, you know, how how can we make this better?

Is there any solution that you think of or what advice would you give

your friends and family when it comes to dealing with smart TV ads

and proxied servers and all this fun stuff?

Please let us know in the comments on YouTube

or you can send us an email at feedback at sharedsecurity.net.

And go check out the comments to see what.

Yeah, yeah, please do.

There's always fun comments.

And I also got great feedback from my request for for comments

on the digital legacy tree. Great.

So yeah, really happy to hear from people and love to hear,

especially ideas around people who, you know, they know it's an important

thing to do. They just haven't got around to it yet.

And so I'd love to hear any of your excuses

for why you haven't created your own digital legacy file.

Awesome. All right, everyone, well, thank you for listening.

And until next time, stay safe, stay secure and stay private.

Thank you for listening or watching.

If you like this episode, hit subscribe, share it with your friends and colleagues

or jump into our community at sharedsecurity.net

slash supporter to keep the conversation going.

Thanks again, and we'll see you next week for another episode of Shared Security.