HeadFlash

Privacy

LG Kills Proxy Apps, EU Extends Chat Scanning, Google Adds Selfie Recovery

LG bans residential proxies from smart TVs; EU renews CSAM scanning until 2028; Proton exposes ACR tracking; Google launches selfie video account recovery.

Listen

LG to Suspend Smart TV Apps That Turn Televisions Into Proxy Nodes

LG Electronics USA plans to suspend any apps built for its smart TVs that turn the television into an always-on residential proxy node. The move follows research by security firm Spur, which found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third parties to route their Internet traffic through a user’s TV. Spur also found that more than a quarter of apps made for Samsung’s Tizen operating system contained similar residential proxy components. LG Senior Vice President John Taylor said the company is working with developers to remove the residential proxy option from their apps on the webOS platform, and developers that fail to comply will have their apps suspended. Taylor stated that LG is committed to keeping residential proxy networks out of its smart TV apps going forward and that the review of those apps is well underway. LG will strengthen its evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs. App makers use residential proxy providers, which pay developers to include SDKs that turn the user’s device into a proxy node rented to paying customers. Spur found such SDKs bundled with games, screensavers, and file utilities. The residential proxy network Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. Bright Data said its network is built on consent and responsibility, with every peer opting in through a dedicated screen and receiving value in return, and with each customer vetted. Bright Data stated that its practices have undergone a second independent audit by PwC. Spur argued that a one-time consent prompt in a TV app is not a substitute for meaningful transparency and oversight, and that the risk is amplified when minors within a household may give consent.

LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security →

EU Extends Controversial Chat-Scanning Regime Until 2028, Excluding End-to-End Encryption

European governments confirmed a temporary regime allowing messaging services to voluntarily deploy measures to detect suspected child sexual abuse material (CSAM), preserving a carve-out for end-to-end encrypted messages. EU ambassadors approved the written procedure on Wednesday, derogating from the bloc’s privacy of electronic communications rules. On Thursday, the file was confirmed as adopted with 25 governments in favour, one against, and one abstention. Member states confirmed the text as passed in the European Parliament earlier this month, including a last-minute amendment removing end-to-end encrypted messaging services such as WhatsApp and Signal from its scope. Privacy advocates have branded the measure ‘chat control’ and warned of a dangerous precedent for scanning private messages. The European Parliament voted against prolonging the measure in March, and it lapsed in April. European Parliament President Roberta Metsola then put the file back on the table at the request of the European People’s Party. Earlier this month, the Parliament voted to extend the temporary regime until 3 April 2028, while EU policymakers continue negotiating a permanent solution with binding rules. In a last-minute move, centre-left lawmakers introduced an amendment excluding end-to-end encryption, which privacy-minded lawmakers hoped would push member states to reject the text. Birgit Sippel (Germany/Socialists & Democrats), the MEP leading the file, said after Parliament adopted the move: ‘A clear majority wanted to limit the scope to known CSAM and include targeted measures. However, due to procedural constraints requiring a qualified majority for amendments to be adopted, we were only able to highlight the crucial protection of end-to-end encryption.’ Last week, the European Commission delivered a favourable opinion on the parliamentary amendments, prompting member states to adopt the file without further negotiation with MEPs. Despite the exclusion of end-to-end encrypted services, several MEPs remain critical. MEP Ignazio Marino (Greens/EFA/Italy) said: ‘Any scanning of the content of private communications must be limited to specific suspects.’ His group voted to reject the prolongation outright, joined by radical left and far-right parties, totalling 276 lawmakers against the provisional scheme. Other political groups split during the vote; the centre-left Socialists & Democrats were mostly in favour, but rapporteur Sippel was among the 20 MEPs voting against. Sceptic lawmakers argue that child protection should not be pursued at the expense of EU citizens’ privacy and the right to secret communications. Marino said: ‘No child is helped by a law that will be annulled by the Court of Justice.’

EU temporarily extends controversial chat-scanning regime until 2028 | Euronews →

Proton Reveals How Smart TVs Use Automatic Content Recognition to Track Everything on Screen

Proton warns that many modern smart TVs quietly collect data about everything displayed on the screen and share it with manufacturers, advertisers, and analytics companies. The tracking is difficult to escape because many privacy controls are buried in settings or enabled by default. Buying a smart TV today often means accepting a level of surveillance that most people never knowingly signed up for. Smart TVs use Automatic Content Recognition (ACR). ACR identifies almost everything shown on the screen, including movies from streaming services, live television, games played through a console, and content from external devices connected via HDMI. The system creates a digital fingerprint of what is playing and matches it against large databases to identify the content. That information can then be shared with TV manufacturers, advertisers, and data brokers to build detailed profiles of viewing habits. ACR runs at the chipset level and is typically switched on by default, so it works even if the TV’s smart features have never been used. Proton says the simplest fix is to keep the TV offline entirely and feed content through a device the user controls, such as a media box or home server over HDMI. For internet access without tracking, tools like Pi-hole can block the TV’s telemetry and ad domains while leaving everything else intact. Users can also disable ACR and other tracking features in the TV’s settings, but the options vary between brands and may not stop every form of data collection. Privacy settings on many televisions are frequently difficult to find, use confusing names, or are turned on by default, making them easy to miss during setup.

Proton reveals how smart TVs track you and the escape situation is pretty grim →

Google Introduces Selfie Video as a New Account Recovery Method

Google introduced a new selfie video option for Google Account recovery. The feature offers an alternative to passkeys, recovery contacts, and other entry methods. To create a selfie video, users look at their device’s camera and perform a series of head movements to capture multiple angles. The video is saved to the account and can be used later to regain access. Google recommends users set up multiple sign-in methods to avoid losing access. The selfie video can be used when a user does not have access to an email address or a trusted device. Google compares the new selfie video to the saved one to grant access. Multiple security layers aim to prevent impersonation attempts such as AI-generated photos and videos. Google stated that selfie videos are encrypted and stored securely, and are used only for sign-in unless the user opts to share them for additional purposes. Videos can be deleted at any time. The feature was previously tested in Brazil. It is designed for Google Accounts only and does not work for Workspace accounts, children’s accounts, or accounts enrolled in the Advanced Protection Program.

You Can Now Recover Your Google Account With a Selfie Video - MacRumors →