TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Samsung Global Privacy Policy - SmartTV Supplement

245 pointsby tschernoover 10 years ago

16 comments

patcheudorover 10 years ago
I recently collected a bug bounty from Samsung on a crypto implementation flaw I found in some of their software. The fix is still being rolled out and given the impact I&#x27;m not going to disclose right now, rather I&#x27;ll let Samsung handle that when the time is right. Anyway, the team at Samsung was responsive and they seemed like they genuinely cared about security. However, based on what I&#x27;ve seen in their products and those from their competitors the first thing I would do is pen-test the voice recognition feature, then turn it off no matter the outcome. The fact is, if it must communicate with a back-end server to work, then it becomes incredibly hard to lock the solution down. Even if the TV is properly validating the public cert of the server when doing the TLS handshake, there&#x27;s got to be a mechanism on the TV for updating the trusted root store because at the end of the day, certs need to expire and thus must be updated. On a few non Samsung smart TV&#x27;s I&#x27;ve looked at over the years, updating the trusted root store on the TV is as &quot;easy&quot; as man in the middling (MitM) the network the TV is on so that web traffic goes to a site I own which has a link to the my.cer root CA that I generated and am using in my TLS MitM solution. From there I just bring up the web browser on the TV, click on the my.cer link and go through the prompts to install the root CA. After that point all traffic from the TV can be decrypted on the wire.<p>Now it is fair to say that the attack I just described requires the ability to MitM the network and have physical access to the device, however, remember that these TV&#x27;s use an IR remote &amp; all an attacker needs is visual access to the TV. If it can be seen through a window it can be controlled through a window and these things typically don&#x27;t require a password to modify the WiFi settings. Some smart TVs also have proxy settings which again, typically don&#x27;t require a password to modify.<p>Given what I just covered, think hotel. From a risk perspective that&#x27;s what I&#x27;d be most worried about. I wonder how many are installing smart TVs with voice recognition? For all other scenarios basically the situation in many cases on the ground is that you are secure because no one is targeting you. In the case of a hotel, someone could be targeting everyone. Such an attack could prove valuable, especially if done in executive suites near financial centers.
评论 #9017962 未加载
评论 #9019074 未加载
评论 #9020480 未加载
评论 #9017998 未加载
amlutoover 10 years ago
It seems to me that, if you have one of these, you live in a two-party consent state (e.g. California), and you invite a guest who hasn&#x27;t clicked the EULA over, then someone is committing felony wiretapping.<p>I would love to see a TV vendor prosecuted for this.
评论 #9017564 未加载
评论 #9017482 未加载
imgabeover 10 years ago
&gt; You may disable Voice Recognition data collection at any time by visiting the “settings” menu. However, this may prevent you from using all of the Voice Recognition features.<p>from here: <a href="https://www.samsung.com/uk/info/privacy-SmartTV.html" rel="nofollow">https:&#x2F;&#x2F;www.samsung.com&#x2F;uk&#x2F;info&#x2F;privacy-SmartTV.html</a><p>So, disable it. I don&#x27;t understand everybody&#x27;s fascination with voice recognition. I don&#x27;t find it more convenient at all. I&#x27;d much rather just push a button. It&#x27;s really not that complicated.
评论 #9017730 未加载
评论 #9017343 未加载
评论 #9017364 未加载
评论 #9017359 未加载
评论 #9017362 未加载
评论 #9017306 未加载
评论 #9018112 未加载
评论 #9017499 未加载
yaddayaddaover 10 years ago
English translation: <a href="https://translate.google.com/translate?sl=auto&amp;tl=en&amp;js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;u=https%3A%2F%2Fnetzpolitik.org%2F2015%2Fsamsung-warnt-bitte-achten-sie-darauf-nichts-privates-vor-unseren-smarttvs-zu-erzaehlen%2F&amp;edit-text=&amp;act=url" rel="nofollow">https:&#x2F;&#x2F;translate.google.com&#x2F;translate?sl=auto&amp;tl=en&amp;js=y&amp;pr...</a>
评论 #9017439 未加载
hughlomasover 10 years ago
I think Amazon&#x27;s Echo device is doing this the proper way, which &quot;uses on-device keyword spotting to detect the wake word. When Echo detects the wake word, it lights up and streams audio to the cloud&quot;. It seems like a technical or design failure on Samsung&#x27;s part to not feature similar functionality.
评论 #9018809 未加载
评论 #9017381 未加载
Animatsover 10 years ago
<i>&quot;Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition.&quot;</i><p><i>&quot;Your SmartTV is equipped with a camera that enables certain advanced features, including the ability to control and interact with your TV with gestures and to use facial recognition technology to authenticate your Samsung Account on your TV.&quot;</i><p>We&#x27;ve come so far since Orwell&#x27;s &quot;telescreen&quot; in &quot;1984&quot;.<p><i>&quot;Big Brother is watching YOU.&quot;</i>
评论 #9018203 未加载
brianpetro_over 10 years ago
This immediately brought to mind Orwell&#x27;s telescreens.<p><a href="http://en.wikipedia.org/wiki/Telescreen" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Telescreen</a>
评论 #9017860 未加载
jsilenceover 10 years ago
Given that voice recognition is possible offline on a RaspberryPi Version 1 [1] I&#x27;m wonderung why they have to send the recorded audio to the cloud in the first place.<p>[1] <a href="https://jasperproject.github.io/" rel="nofollow">https:&#x2F;&#x2F;jasperproject.github.io&#x2F;</a>
评论 #9017717 未加载
_asummersover 10 years ago
As far as networking is concerned, what should I google for separating a device like this onto its own internal private network? I have devices that I want to whitelist traffic for while not affecting other devices in my home.
评论 #9017509 未加载
评论 #9017502 未加载
评论 #9017443 未加载
评论 #9018087 未加载
ChuckMcMover 10 years ago
Interesting, there is the vocal recognition thing but the camera equipped to do facial recognition is much more worrisome. Check into a hotel room wearing a ski mask, sneak up to the TV and put tape over the camera if you can find it.<p>Nothing like downloading the facial recognition features of Carmen San Diego into all the hotel TV&#x27;s in a country to see where she is staying.<p>License plate readers don&#x27;t hold a candle to this. Now to check to see if every Samsung TV coming into the US has to go through &#x27;special customs checking&#x27; ...
frikover 10 years ago
It&#x27;s not only Samsung Smart-TV but all cloud-based speech recognition products, right?<p>(Nuance&#x2F;Apple Siri, Microsoft Cortana, Google Now, IBM Watson Speech, Amazon Echo, LG-Smart TV, etc.)<p>From a consumer perspective you want an offline speech product like Nuance Dragon NaturallySpeaking: <a href="http://en.wikipedia.org/wiki/Dragon_NaturallySpeaking" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Dragon_NaturallySpeaking</a> (it&#x27;s the same technology that powers Nuance cloud based products like Apple Siri, IBM Watson, etc.)
评论 #9017704 未加载
apiover 10 years ago
Why is the cloud required for speech to text when a four core ARM SOC is under 15 dollars? My Commodore 64 had good text to speech, and Dragon was doing speech to text on 90s PCs. I don&#x27;t get the technical rationale.
评论 #9019308 未加载
aw3c2over 10 years ago
If you submit things from aggregators, please try to find the actual source and submit that instead.<p>Submitted: <a href="https://netzpolitik.org/2015/samsung-warnt-bitte-achten-sie-darauf-nichts-privates-vor-unseren-smarttvs-zu-erzaehlen/" rel="nofollow">https:&#x2F;&#x2F;netzpolitik.org&#x2F;2015&#x2F;samsung-warnt-bitte-achten-sie-...</a> which links to <a href="http://martingiesler.tumblr.com/post/110325577280/samsung-watch-what-you-say-in-front-of-our-tvs" rel="nofollow">http:&#x2F;&#x2F;martingiesler.tumblr.com&#x2F;post&#x2F;110325577280&#x2F;samsung-wa...</a> which links to <a href="http://mostlysignssomeportents.tumblr.com/post/110300533107/samsung-watch-what-you-say-in-front-of-our-tvs" rel="nofollow">http:&#x2F;&#x2F;mostlysignssomeportents.tumblr.com&#x2F;post&#x2F;110300533107&#x2F;...</a> which links to <a href="http://boingboing.net/2015/02/06/samsung-watch-what-you-say-in.html" rel="nofollow">http:&#x2F;&#x2F;boingboing.net&#x2F;2015&#x2F;02&#x2F;06&#x2F;samsung-watch-what-you-say-...</a> which links to <a href="http://www.reddit.com/r/technology/comments/2uuvdz/samsung_smarttv_privacy_policy_please_be_aware/" rel="nofollow">http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;technology&#x2F;comments&#x2F;2uuvdz&#x2F;samsung_s...</a> which references <a href="https://www.samsung.com/uk/info/privacy-SmartTV.html" rel="nofollow">https:&#x2F;&#x2F;www.samsung.com&#x2F;uk&#x2F;info&#x2F;privacy-SmartTV.html</a><p>On the other hand, the HN rules suggest doing things like this if you want to cherry pick a certain aspect of a page...
评论 #9017611 未加载
Havocover 10 years ago
Has been in the news before. Voice recognition is done on a server farm meaning it needs to get sent there &amp; possible get intercepted.<p>Not ideal but doesn&#x27;t strike me as a big risk
teapoweredover 10 years ago
It&#x27;s about targeted advertising - arguing with your spouse? Next ad break we show you adverts for lawers.
评论 #9017722 未加载
shmerlover 10 years ago
A good lesson why one shouldn&#x27;t use any systems with DRM. People are so upset about mass surveillance by the government, yet they readily subject themselves to mass surveillance of DRM systems. Where is logic?