LG is tightening smart TV security by blocking residential proxy apps

LG Electronics USA has announced that it plans to suspend apps for its smart TVs that can turn a television into a residential proxy node.
Recently, security firm Spur reported that nearly half of all apps available for LG smart TVs contain code that can turn a television into a so-called residential proxy.
A residential proxy is an intermediary for internet traffic that uses the IP address of a private internet user. These IP addresses are assigned to consumer devices by internet providers or manufacturers of IoT equipment. Therefore, they are registered as ‘residential’ in IP databases.
When a residential proxy is deployed, the recipient’s internet traffic is redirected through the device and network of a home user. As a result, it appears as if the traffic originates from a normal consumer, and not from an automated system or server affiliated with the source of the network traffic.
A residential proxy offers all sorts of advantages for hackers. For example, an attacker can hide his own IP address, making it harder for law enforcement authorities to track his location.
On top of that, he can select an IP address that’s located in the same region as the target. Logging in from the same region as the target is less suspicious than logging in from another country.
Lastly, a device that has been turned into a residential proxy can become a foothold for reaching things that were never meant to be exposed to the internet: router admin panels, NAS devices, printers, cameras, developer machines, and other apps listening on local ports. This is how the Kimwolf botnet was created.
Turning a smart TV into a residential proxy can be done in several ways. App developers can integrate a software development kit (SDK) in their app. Once a user installs it, the SDK makes sure that the smart TV becomes part of a proxy service.
Other ways to turn a smart TV into a residential proxy include hiding it in the terms and conditions, hacking Internet of Things (IoT) devices, deploying malware, and knowingly installing proxy software in exchange for payment.
John Taylor, Senior Vice President at LG, suspects that the first method is being exploited to turn LG smart TVs into residential proxies.
“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended,” he told security expert Brian Krebs in a statement.
To keep residential proxy networks out of LG’s smart TVs, the company is currently strengthening its evaluation process for apps submitted by developers.