7 ms·
Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release
by Retr0id 9d ago
Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.
- minetest2048 9d agoI'm guessing that you're exploiting some sort of exploit (buffer overflow???) on the DVB-T demodulator
- delta_p_delta_x 9d ago> only RF down the TV antenna input Holy shit. RF to zero-click exploit is a new one. I guess digital-everything wasn't always a good idea, this probably wouldn't ever have been a problem with analogue antennas and CRTs. What are the people at LG even doing?
- Ekaros 9d agoTeletext was available in analogue times. So I could well imagine there to be a possible avenue of exploits with it too. Would take a bit of time, but I see no reason why wouldn't some data result in a incorrect handling.
- hnlmorg 9d agoExploiting what? There wasn’t any software hierarchy for Teletext to escape from in analogy TVs. If you found a bug in the Teletext chip you couldn’t then go on to do anything to the TV set aside print different data to the screen. And since you’re already tuned into that radio frequency and controlling the data sent on it, you already have control of what’s sent to the TV screen already anyway so who cares? As an aside, I once interviewed one of the guys who wrote Teletext processors for analog TVs. He was a very interesting individual.
- rickdeckard 9d ago> Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it. So no responsible disclosure, I see. Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything. So you'd need some very specific f/up exploit to then change local settings on the device I imagine. Either way, would be a great opportunity to demonstrate this in a video, now that there's attention on the topic, to further amplify the pressure on LG's "terrible security posture" as you say.
- Retr0id 9d ago> So no responsible disclosure, I see. Huh?
- rickdeckard 9d agoYou stated that you're "sitting on one that doesn't even require an internet connection [..] I'm waiting for my model to go EOL before I release it" I read this as "Wait until the model is EOL, hoping it won't be disclosed and fixed until then and also not fixed afterwards" Is this not what you meant to say?
- mort96 9d agoResponsible disclosure makes sense when the user and the manufacturer have the same goal of the product being secure. Jailbreaking is a case where the user and the manufacturer have opposing goals: the user wants to be in charge their hardware, the manufacturer wants to prevent the user from being in charge of their own hardware. Responsible disclosure doesn't make sense, the manufacturer would just patch the vulnerability before users could use it. If manufacturers had a sanctioned way for the user to get root access to their own hardware, responsible disclosure would've made sense, but as it is, vulnerabilities are a useful tool for the owner of the device.
- 9d ago