LG Electronics is removing residential proxy features from its smart TV apps, ensuring user privacy while improving app evaluation processes.

LG Electronics USA has announced a significant step to enhance user privacy by suspending any apps on its smart TVs that enable residential proxy functionality. This decision follows a disturbing finding from security researchers that revealed over 42% of games and applications available in LG’s webOS store incorporate third-party software that could reroute internet traffic through users' televisions.
Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions. Image: Spur.us.
This issue was highlighted in a recent report by Spur, which examined the usage of residential proxy software development kits (SDKs) in smart TV applications. Aside from LG, the study noted that over a quarter of Tizen OS apps from Samsung exhibited similar residential proxy features.
In response to these findings, John Taylor, LG’s Senior Vice President, confirmed in a discussion with KrebsOnSecurity that the company is actively collaborating with app developers to eliminate the residential proxy capability from their offerings on the webOS platform. If developers do not comply, LG will suspend their applications.
“Using LG smart TVs as a residential proxy network is not an intended purpose. We are currently working with developers to remove this functionality,” Taylor commented. “If developers do not take action, their apps will not remain on our platform.”
He also stressed that LG is committed to preventing residential proxy networks from finding their way back into its smart TV apps and mentioned that a review process is already in effect.
“To enhance our platform quality and user experience, LG will strengthen our evaluations of developer-submitted applications, including those using residential proxy SDKs,” he added in an emailed statement.
For many app developers, monetizing through residential proxy services can be tempting. These services often compensate developers for including SDKs that turn users' devices into proxy nodes for rent. Spur found that proxy SDKs could even be bundled with basic applications such as simple games and file management tools.
A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us.
The study highlighted that Bright Data primarily dominated the residential proxy SDK market across both LG and Samsung smart TVs. In a statement provided to KrebsOnSecurity, Bright Data defended its practices, noting that their network operates on principles of consent and accountability, adhering to the standards set by LG and Samsung.
“Every user opts in via a dedicated prompt and receives value in return; our customers are thoroughly vetted, and our processes have undergone a recent independent audit by PwC,” the statement read. “We remain committed to fostering an open internet where legitimate businesses and institutions can responsibly access public data.”
Bright Data and other mentioned proxy services claim they implement strict know-your-customer protocols to ensure their services are not misused. They also employ technological measures to prevent clients from accessing and controlling other devices on a user's local network.
Spur’s report raises an important point: the challenge lies not in the existence of residential proxy networks but in their widespread integration into devices that everyday consumers view as simple televisions and may not adequately scrutinize.
“A one-time consent prompt buried in a TV app lacks sufficient transparency and ongoing oversight,” remarked Trevor Sutter from Spur. “The risks multiply when consent is unintentionally given by those who shouldn't, such as children in the household.”
While LG's move to eliminate residential proxy SDKs is a positive development, the company recently faced criticism for promoting McAfee security products unbidden through its high-end LCD monitors. Reports surfaced showing that particular LG monitors automatically installed an app to promote paid subscriptions to McAfee antivirus, delivered via Windows Update without user consent.
Update, July 22, 1:06 p.m. ET: Added statement from Bright Data.
Discussion
Sign in to join the discussion.