It’s not just LG. Every TV company is spying on you

The world of television has been a focus of controversy thanks to a two-hour and 15-minute video from Gamers Nexus that claims that LG televisions are nefariously spying on everything you do. They can record and store audio even when they appear to be turned off, track everything you look at, and could even be hacked remotely and turned into covert surveillance devices. LG TV owners and tech enthusiasts in general are furious, and a hasty response from LG has done little to calm the situation. Some of the claims in the video may be based on speculation and assumptions, but many of the core concerns are real and widespread. While LG was the focus of the video, all TV companies track what you do, collect that data, and share it with their partners. And we are okay with it, even if we don’t realize it. Television prices have dropped significantly over the years, to the point that some companies are selling them at a loss. But they make up for that shortfall by selling user behavior data they collect from the operating system. That’s why Walmart bought Vizio in 2024. There’s a lot going on in the Gamers Nexus video, but we’ll start with the part that almost everyone who makes TVs does: track what you watch, when you watch, where you watch, and how you watch to sell you things about everything. Automatic content recognition (ACR) systems are built into almost all modern TVs and can identify content being played through built-in streaming apps and through TV ports by taking fragments of audio or video, turning them into fingerprints, and sending them to a database for identification. It’s what allows a TV to make content recommendations, as well as serve you ads based on your viewing habits. It’s also a way for companies like Nielsen to track audiences across platforms and services. For televisions to capture this information, it must be accepted. One of Gamers Nexus’ complaints in the video is that this consent is often hidden in long, confusing agreements you must agree to in order to use the TV, and that companies often use obscure patterns or deceptive designs to get users to agree to things without realizing they didn’t have to. For example, the Gamers Nexus video showed an LG TV displaying six different user agreements, including one that accepted ACR, and automatically placing the cursor on “Select All” when only two agreements are required to continue. As a TV reviewer, I have to deal with end user license agreements (EULAs) and privacy policies on every product I review. And while it may be a losing battle given the sheer number of TVs and other smart devices that come into my apartment, I take steps to try to protect my privacy. I have a disposable Gmail account that is used only to log into apps and the TV operating system. Initially, I only accept the documents legally required for the TV to function properly and to perform my image quality tests, both Calman and test discs. I never accept automatic content recognition, which is referred to by names including Enhanced Viewing, Smart TV Experience, and Samba Interactive TV. I also review all the menus, partly to familiarize myself with all the available settings, but also to make sure any ads or data tracking are turned off. When I need to test voice control, I accept the voice recognition agreements before testing the functionality. And since this is usually the last thing I do in my testing process, this is followed by a factory reset before sending the TV to the manufacturer. If you are concerned about privacy, do not use voice control. Or if you do, just use the one from a separate transmission box from a brand you trust. I recommend the same for everyone who has a smart TV. Have a dedicated email for logging in on TVs (and, if possible, your streaming apps) that isn’t connected to your personal email. When setting up the TV, only accept what is necessary for it to work if you want to use its operating system. And after setup, review all menu options to make sure ad tracking is turned off and read the menu prompts carefully, as the wording is sometimes confusing (probably intentionally). Consumer Reports has an excellent, if slightly older, guide to limiting data collection from different TV manufacturers. To take it a step further, turn off Wi-Fi and disconnect the Ethernet cable from the TV and basically use it as a dumb TV (the Vizio Mini LED Quantum I reviewed is the best at this). Then, connect the third-party streaming device of your choice. I use an Apple TV 4K. Not because I don’t think Apple collects any data, but because it doesn’t use ACR and I trust its security protocols more than any of the TV manufacturers or Google. Apple still offers content recommendations based on what you watch, download, browse, and subscribe to in the Apple TV app. This can be disabled in settings by going to Apps -> TV -> Use playback history -> Off. For third-party apps, such as Netflix or Disney Plus, Apple offers users the option to “Ask the app not to track,” which prevents the app developer from accessing the system’s advertising identifier. Please note that each streaming service tracks your usage within its own app and links it to your login; many streaming boxes do this too. A good portion of the Gamers Nexus video focused on broader security concerns and what appear to be much more egregious privacy violations by LG. That includes recording video and audio from the room even when the TV appeared to be off, sending information about the local network to LG’s servers, and recording background audio captured when using the TV’s microphone for search and voice control. Nexus and Level1Techs players were even able to exploit security vulnerabilities to take control of the TV, thus discovering the above. None of that is good, obviously. But it’s worth noting that the scariest part – recording video (from a webcam they connected) and audio when the TV appeared off – appears to have been possible only because Level1Techs rooted the TV using an exploit that they said requires network access. If you have access to a computer, which is what a smart TV is, and you can root it, you can make it do pretty much anything you want. If the TV is truly rootable with network access only, this is a legitimate security issue; It still requires an attacker to break into your private network, but gives them a vulnerable endpoint if they do. With that root access, Gamers Nexus also discovered that when an LG TV’s microphone was activated for voice search, it continued recording for 10 to 15 seconds after it last detected voice. It could also detect the wake word “hello LG” and other words from further away than expected, after Gamers Nexus enabled the far-field microphone and increased the microphone sensitivity. Taken together, that means that as long as someone within (long) ear range of the microphones continued speaking after the microphone was activated, the TV would also capture their conversation and treat it as part of the voice search. That’s not ideal, but Gamers Nexus and Level1Techs did their best to increase the microphone’s pickup range and used the optional voice search wake word, both of which are easy to avoid. Gamers Nexus rooted the LG TV so it could access and view the data it was collecting in real time. Image: Gamers Nexus In addition to its pretty damning evidence, there’s also a lot of “might” and “we think” and outright speculation in the video, not to mention the long-distance conclusion jumps. For example: Steve Burke of Gamers Nexus says that unplugging the Ethernet cable from your TV might not be enough to stop streaming data to LG, because it might automatically connect to open Wi-Fi streams from the neighborhood of Comcast or AT&T customers in order to upload that data. There’s no evidence in the Gamers Nexus video that LG TVs actually try to do this (these hotspots require user accounts, for starters) and Burke doesn’t say they do, or even could, but the implication is clear. This type of rampant speculation undermines the legitimate vulnerabilities that Gamers Nexus highlights. There’s really no way to completely protect yourself from your TV, streaming device, or streaming services collecting your data, at least right now. So much money is made at the expense of consumers and data collection is so integrated into the operation of these companies that change and regulation must come from government policy makers. “We need a comprehensive federal privacy law that covers this type of data collection and misuse,” said Thorin Klosowski, senior security and privacy activist at the Electronic Frontier Foundation (EFF). “Specifically one that requires consent, no deceptive design tricks to obtain that consent, and a data minimization requirement, which would limit companies to using data only for what is needed to provide the service.” The fact that we, as users of technology products, need to actively protect ourselves from companies that sell us things is bad. But it is the unfortunate reality today of living in a world full of technology and taking advantage of the benefits that today’s technology offers. Beyond completely disconnecting and living in a cabin in the woods with a dumb TV and a collection of Blu-rays, the best thing we can do is limit information sharing as much as possible. If it’s possible to keep it private, we should do it. Follow topics and authors of this story to see more like it in your home page’s personalized feed and receive email updates. John HigginsCloseJohn HigginsSenior Reviewer, TVs & AudioPosts from this author will be added to your daily email digest and homepage feed.FollowFollowView all by John HigginsGadgetsCloseGadgetsPosts from this topic will be added to your daily email digest and homepage feed.FollowFollowView all gadgetsLGCloseLGP posts from this topic will be added to your daily email digest and to your homepage feed.FollowFollowView all LGTechCloseTechPosts in this topic will be added to your daily email digest and homepage feed.FollowFollowView all TechTVsCloseTVsPosts in this topic will be added to your daily email digest and homepage feed.FollowFollowView all TVs