mrkeyoor.com_
Sun 13 Sept 10:47 UTC
Tech6 min read

LG's TV Denial Leaves Plaintext Voice Logs Unanswered

LG explains when its TVs listen and confirms local-network scans, but its rebuttal does not account for the plaintext voice transcripts found by researchers.

LG's rebuttal to a smart-TV privacy investigation had reached 503 points and 395 comments on Hacker News by MrKeyoor's September 12 crawl. That reaction is a community-interest signal, not proof that every allegation is correct. The response itself confirms that some televisions process audio for a wake word in standby and scan the local network, yet it does not explain the plaintext voice transcripts researchers say they recovered.

The number attached to the original report needs similar care. The 216 million figure comes from LG Ad Solutions' own factsheet, which describes global addressable smart-TV inventory for advertisers. It is a measure of commercial reach. It does not mean researchers tested 216 million televisions, found 216 million vulnerable sets, or proved identical behavior across that fleet.

What LG denied

LG told Tom's Hardware that its TVs process voice data when a person holds the voice button or when an enabled far-field system recognizes "Hi LG." It said other ambient conversations are neither collected nor recorded. Unrecognized wake-word audio, according to the company, is processed on the television, immediately deleted, and never sent to its servers.

That explanation confirms a narrower point that headlines can easily blur. LG's voice-command documentation says compatible sets can turn on after hearing "Hi LG" while apparently off, provided direct voice recognition and either Always Ready or Quick Start is enabled. A dark panel is therefore not necessarily a fully powered-down television.

LG's Always Ready guide is even plainer: voice recognition can be triggered while the background screen is off, and the mode does not operate after the power cord is removed. Model, firmware, region, and settings all matter. Any account that collapses "screen off," "standby," "offline," and "unplugged from mains power" into one state loses the technical distinction needed to judge the claim.

The missing artifact is text

The Gamers Nexus investigation, produced with Level1Techs and security researchers, reports two kinds of evidence: network captures showing native data flows and access to files inside tested webOS televisions. The team says it found voice-derived text stored in plaintext. It also separates behavior present on retail sets from covert recording made possible after a television was compromised. Those are related privacy and security issues, but they are not the same finding.

Ars Technica's account says the researchers used Wireshark on LG OLED models and found local-network scanning that did not require an exploit. The audio portion went further: researchers reported retrieving locally stored material and discussed remote-code-execution flaws that were still moving through coordinated disclosure. A product feature can explain why a microphone and speech pipeline exist; a software flaw can change who controls that pipeline.

LG's statement deals with intended activation and server transmission. It does not say what created the plaintext transcripts, how long those files remained, which process could read them, or whether they were produced only after a valid wake event. Tom's Hardware explicitly notes that the company did not address the stored transcripts and that the publication had not independently verified either side. Calling all claims false does not answer the filesystem evidence at the center of the dispute.

Plaintext changes the security question even if no file ever leaves the television. Searchable words are easier for another local process or an intruder to inspect than a short-lived audio buffer. Their presence alone does not prove transmission, so a server-side allegation still needs matching network traffic. The research report and LG response leave that precise chain unresolved.

A useful vendor response would identify the affected webOS versions and television models, document the trigger that creates a transcript, state its retention period, and describe whether any component uploads it. The original video's chapter list places plaintext transcripts, ambient conversation, audio playback capture, and vulnerabilities in separate sections. LG's reply groups them under a general description of normal voice recognition, leaving readers unable to map its answer to each test.

For an independent reproduction, a lab would need clean and compromised televisions on the same firmware, one setting changed per run, saved packet captures, and filesystem snapshots before and after each voice event. Ars reports the use of Wireshark and names one tested G3 model, but the cited public reports do not provide a corpus that lets outside teams compare every state. Without those artifacts, observers can see the demonstration while still disagreeing about its boundaries.

Network discovery and advertising consent are separate questions

LG also confirms that its TVs scan for nearby devices on the same network. The company calls this a standard smart-TV function used for connectivity, content sharing, and smart-home features, according to Ars Technica. The investigation says tested sets enumerated unrelated devices and collected nearby Wi-Fi details. Whether discovery is common does not establish which fields are necessary, which stay local, or which reach an advertising system.

Automatic content recognition, or ACR, is another data path. It fingerprints material playing on a television so that content can be identified, a process described in the FTC's Vizio case. LG says ACR is opt-in and that its data is not used for advertising without consent, as quoted in the company's response. That claim does not by itself explain LAN discovery or voice-log retention. A single privacy toggle cannot be assumed to govern every subsystem inside webOS.

LG's current user-agreement guide says agreements covering viewing information, voice features, and personalized advertising are optional. It also says the main Terms of Use and Privacy Policy are required for smart services such as Netflix and YouTube. Owners can revisit their choices under Settings, Privacy & Terms, then User Agreements. Menu wording may differ by model, but the distinction between required platform terms and optional data uses is LG's own.

Consent must also describe the collection clearly. In 2017, the US Federal Trade Commission said Vizio had tracked viewing histories on 11 million smart TVs without adequate notice or consent; the settlement required prominent disclosure and affirmative consent. That case concerned another manufacturer and does not decide LG's conduct. It does show why the label on an option matters less than what the interface tells a buyer will be collected and shared.

The 216 million figure needs a denominator

LG Ad Solutions markets access to 49 million US televisions and 216 million globally. Those figures describe screens advertisers may address. The investigation examined a small set of retail LG OLED televisions, including G-series hardware, and Ars identified a G3 used for packet capture. Neither source provides a fleet-wide count of devices that store transcripts or share the same disclosed flaws.

A defensible scope statement needs a matrix of model, webOS build, region, enabled agreements, voice settings, power state, and network state. The LG support material already says features and menu paths vary by model. Until LG or independent labs publish that matrix, 216 million is context for the business incentive and potential reach, not a measured affected population.

What owners can do now

Owners who do not use hands-free control can disable voice recognition and Always Ready using the paths in LG's voice settings and Always Ready documentation. They can also review the optional viewing-information, voice, and personalized-ad agreements. These controls reduce enabled collection paths, though they do not prove that every disputed network request has stopped.

Disconnecting a television from the network removes its direct route to LG's servers, but it also blocks app and firmware updates delivered through that connection. The FTC advises owners of connected devices to install firmware updates, disable unused features, and review smart-TV tracking settings. With alleged code-execution flaws still under disclosure, abandoning updates creates a different risk. People who want a display with no online services can keep the TV offline and use a separately managed player, understanding that the player has its own privacy terms.

The next useful evidence will be less dramatic than another denial: an LG model-and-firmware table, an explanation of the plaintext transcript files, and patches or advisories for the reported code-execution flaws. Tom's Hardware says neither the investigation nor LG's counterclaims were independently verified. Until reproducible tests close that gap, LG's response narrows how the company says its voice system should work, but it does not account for what researchers say they found on disk.

We reviewed this

  1. Speech — our honest review
  2. servers — our honest review
  3. pipeline — our honest review

Sources

  1. LG strongly denies TV spying claims
  2. Hacker News discussion of LG's denial
  3. 216,000,000 Spy TVs: The LG Smart TV Problem
  4. LG TV shown scanning LAN for third-party phones and other devices
  5. LG TV: Using Voice Commands
  6. LG TV: How to Use the Always Ready Feature
  7. How to Accept the Updated User Agreements on Your LG TV
  8. LG Ad Solutions global addressable TV factsheet