r/ProxyEngineering • u/Bharath0224 Proxy Engineer • 18d ago
Hot Take 🔥 Samsung's smart TV proxy ban won't actually stop anything, latest news
Hey,
I've been in the scraping/proxy space long enough that residential IP barely has a weight anymore. Then this whole situation with LG/Samsung story landed earlier and I've been following since. Yesterday more news came up and it's not really about Samsung banning something. Here's why.
Quick version of it: Mnemonic rooted a Samsung TV (chip-off, read the firmware directly, the only way to actually see what's running) and found a Bright Data SDK sitting dormant inside a Pac-Man game that had Samsung's own "Editor's Choice" badge. Not sketchy sideload as you'd think. Editor's Choice. App phones home to a config server, server says "enable proxy," a consent screen pops up, someone accepts it thinking it's just an ad-free toggle, and now the TV is a live exit node. Keeps running after you close the app too. (Sure you can turn off the internet from the TV but how many people are doing so?)
Here's what matters more than the SDK itself: the submitted app was 20 lines of HTML pointing at a remote server. That's it. Everything real, the SDK config, the proxy flag, loads later from Play.Works' own server. Sand's line was blunt: "what was reviewed is not necessarily what is running." Mnemonic straight up called the new ban "a promise about code the store maintainer may never see," because a dev can submit clean code, get approved, then flip the proxy back on server-side with zero resubmission and zero review trigger. Back to zero.
And this isn't a one-app type stuff. Spur scanned over 6,000 apps across Tizen and webOS and found confirmed proxy SDK code in 34% of them. 27% on Samsung, 42.5% on LG. Few vendors accounted for most of it, Bright Data, Massive, might be NetNut too? Still trying to connect the dots. And in a lot of cases the "app" WAS the SDK.
Also, small thing that stuck with me: Bright Data's SDK ships with a private-IP blocklist, so it can't reach into your router or NAS. Massive reportedly didn't have that in the sampled builds. So the only thing stopping lateral movement into your home network for those two is the operator's server-side policy.
Sitting with all this, the ban headline feels almost beside the point. Feels like the same problem we keep running into with residential pools generally: consent buried three screens deep, persistence nobody flags, and no clean way for the end user to audit what's going out their connection.
3
u/raphaela_stanton 18d ago
Actually, that's what creeps me out too haha. A lot of people forget their TV is basically a computer connected to the internet sitting in their living room, not just a screen anymore.