Slashdot Mirror


Programmer Finds Way To Liberate Ransomware Affected Smart TV, Thanks To LG (theregister.co.uk)

Television production factory LG has saved Darren Cauthon's new year by providing hidden reset instructions to liberate his Google TV from ransomware. From a report on The Register: The company initially demanded more money than the idiot box was worth to repair the TV and relented offering instructions for resetting the telly after Cauthon took to Twitter to express his displeasure. The infection came after the programmer's wife downloaded an app to the TV promising free movies. Instead, it installed the ransomware, with a demand of US$500 to have the menace removed. Cauthon said LG offered factory reset steps which are not publicly revealed nor known to its customer support technicians. He says a family member showed him the TV over Christmas laden with ransomware purporting to be a FBI message bearing a notice that suspicious files were found and the user has been fined.

10 of 161 comments (clear)

  1. Welcome by burtosis · · Score: 5, Insightful

    Welcome all to a world where you don't own nor are allowed to alter the software on items you purchased outright. Be glad that you can still begrudgingly get the information you need on some products to restore an item to factory condition. Remember, only criminals want to tamper with the perfection companies provide. Want to modify something? Be prepared for jail time.

    1. Re:Welcome by Lord+Kano · · Score: 3, Insightful

      That's like saying you ate at a restaurant, so you're now partial owner of that restaurant and demand access to their secret recipes.

      It's more like saying that since you paid for the food, you have the right to add salt, pepper or any other seasoning of your choosing in order to enjoy the food, that you purchased, in the manner that you choose.

      LK

      --
      "Hi. This is my friend, Jack Shit, and you don't know him." - Lord Kano
    2. Re:Welcome by Aaden42 · · Score: 4, Insightful

      Show me where in the terms is said, "While this television is an Android-based computer and reasonably accepted industry standards include a way of reloading fresh operating software from scratch on such computers, this computer has no such function."

      The "everything's a computer" IoT industry has a LONG way to go in terms of disclosing limitations of the devices they're producing. Both sides of the techy and non-techy world have expectations for these devices that are generally agreed upon for other devices of their type in either the consumer electronics or computing device camps. Non-techies have a reasonable expectation that a TV is a box that shows pictures and can't be infected by malware. Techies understand that smart TV's are actually computer that might have malware vulnerabilities and further presume that like all other computers they should have some way to reset them and completely erase any infection.

      Manufacturers are falling short of both camp's expectations, and they're also failing to disclose the true nature of the devices to consumers. They're producing devices that are simultaneously unprecedentedly vulnerable by TV standards and unrepairable by computer standards. The only way for a consumer to find these things out is to buy it and find out the hard way. That's not acceptable.

  2. Re:programmers wife!... by The-Ixian · · Score: 5, Insightful

    I am still trying to figure out why the person's profession or skill set even matters in this story?

    "LG gives user unpublished reset instructions" is more appropriate of a title.

    --
    My eyes reflect the stars and a smile lights up my face.
  3. Don't buy a smart TV by Viol8 · · Score: 4, Insightful

    They have no purpose. Most people now simply use TVs as monitors for a set top box and if you need any more functionality simply plug your computer or tablet into a normal TV. Why anyone would pay a significant extra amount of cash for an oversized underpowered android tablet I have no idea.

    1. Re:Don't buy a smart TV by nasch · · Score: 3, Insightful

      It will probably get harder and harder to find a TV without these "smart" features. If you don't want them, just don't give the TV your wifi password.

    2. Re:Don't buy a smart TV by vux984 · · Score: 5, Insightful

      It will probably get harder and harder to find a TV without these "smart" features. If you don't want them, just don't give the TV your wifi password.

      We are fast approaching a time where the TV will come with built in cellular data, and lifetime subscription (for specific uses). I've already seen several devices that have this scheme... for example a 'cloud punch clock'.

      You might have to enter your wifi password to stream 4k from netflix, but it might send its telemetry, get advertising updates, firmware updates, and its cloud 'siri/cortana/google voice recognition stuff' via a separate always-on cellular network connection.

      The price of the chipset itself is small in a $2000+ TV; and the cost of prepaid data measured at likely less than 500MB per years for 10 years, bought at wholesale for a million TVs at once... well... that's also going to be pretty small.

      Right now the IoT is at least theoretically constrained to our wifi and runs through our firewalls. But we're fast approaching the time where it's just directly connected to the carrier bypassing our home networks entirely.

      Indeed, our home networks themselves may become a nerd relic, the way home servers are. Your computer connects to the cloud, your printer connects to the cloud, your TV connects to the cloud... who needs a LAN? Sure a LAN would be faster... but once its good enough the average user will be happy to forgo having to maintain a home network in exchange for 'it just connects to the cloud'.

  4. Re:programmers wife!... by TWX · · Score: 4, Insightful

    Well, a programmer is probably technical enough to understand that the device might have a factory reset function, and if it turns out that the wife is being scapegoated, a programmer is also likely in a position to know enough to be dangerous.

    One of the biggest problems in IT and CIS is the assumption that if one is capable on one's particular field, that one is capable in all fields. This simply isn't true in most examples; most people are jack-of-all-trades or are master of a single discipline, and some are jack-of-all-trades and maybe master of one or two in particular. No one is master of all trades.

    I will agree that the bulk off the summary is crap. It goes off onto a tangent but doesn't adequately flesh-out that tangent.

    --
    Do not look into laser with remaining eye.
  5. What's the alternative? by mi · · Score: 4, Insightful

    Don't buy a smart TV. They have no purpose.

    They offer, what the manufacturer believes you want in one package.

    I too would rather just buy a nice 65" monitor — because I have a capable set-top box running my IPTV apps and a nice surround-sound setup already — but there aren't any good ones for sale. Or, rather, there are, but they all have the "smart TV" built into them — and I am as annoyed about paying for the "smart" features and the extra hardware they require (USB-readers and WiFi), as people used to be about paying the "Microsoft Tax".

    But there is no alternative at the moment. Which means, people like me (and you) are a tiny minority... I guess, it would cost the manufacturers more to make and ship the separate models without these add-ons, than to simply bundle it all in.

    --
    In Soviet Washington the swamp drains you.
  6. that reset info should be public knowledge by FudRucker · · Score: 4, Insightful

    customers should be allowed to do factory resets on their televisions, WTF is wrong with LG, that info should be in the documentation that comes with every new television sold!!!

    --
    Politics is Treachery, Religion is Brainwashing