Gamers Nexus: Ernstige Privacyproblemen met LG Smart TV's

Pagina: 1
Acties:

Onderwerpen


  • Wim1147
  • Registratie: April 2023
  • Laatst online: 13:20
Volgens het bekende YouTube kanaal Gamers Nexus zijn er serieuze problemen met LG Smart TV's. In de aflevering 216,000,000 Spy TVs | The LG Smart TV Problem die hier is te zien wordt dieper ingegaan op de problemen met de Automatic Content Recognition (ACR) van LG Smart TV's en op televisietoestellen die zelfs de gesprekken van gebruikers en hun directe omgeving registreren wanneer het toestel niet is verbonden met het internet. Misschien is het de hoogste tijd om dergelijke toestellen te vervangen voor toestellen die niet 'smart' zijn.

  • John Doos
  • Registratie: Februari 2010
  • Laatst online: 16:19

John Doos

ClaudZaque

Inmiddels heeft de redactie er een post aan gewijd:

nieuws: LG-smart-tv's lijken gebruikers af te luisteren en netwerken te scannen

Nee


  • Gulli
  • Registratie: Oktober 2001
  • Laatst online: 07-09 13:40

Gulli

100% Unwiderstehlich

Misschien kunnen we een simpel polletje maken voor mensen met een LG-TV in de Benelux om te kijken of LG zich netjes aan de regels houdt. Dit onderzoek komt uit de VS maar daar is het internet nog een Wilde Westen van 'mogelijkheden' voor fabrikanten. Ik neem aan (grote aanname!) dat dit in de EU wel aan banden is gelegd.

Geldt natuurlijk ook voor andere merken. Samsung is bijvoorbeeld ook geen heilige, geen idee hoe Philips/TCL zich gedragen

[ Voor 1% gewijzigd door Gulli op 07-09-2026 12:51 . Reden: typo ]

Connaisseur des femmes


  • vrieske
  • Registratie: Juli 2004
  • Laatst online: 14:01
Ik heb zelf de lg domeinen al een tijd (enkele jaren)in pihole banlijst staan. Daarmee breekt wel de lg store enzo en de apps die je geïnstalleerd hebt staan moet je van hopen dat het blijft werken. Maar goed ik heb alleen jellyfin en youtube app geïnstalleerd.

Maar gezien dit nieuws wellicht tijd om nog wat meer te blokkeren op netwerk / firewall niveau..

  • Wim1147
  • Registratie: April 2023
  • Laatst online: 13:20
Gulli schreef op maandag 7 september 2026 @ 12:50:
Misschien kunnen we een simpel polletje maken voor mensen met een LG-TV in de Benelux om te kijken of LG zich netjes aan de regels houdt. Dit onderzoek komt uit de VS maar daar is het internet nog een Wilde Westen van 'mogelijkheden' voor fabrikanten. Ik neem aan (grote aanname!) dat dit in de EU wel aan banden is gelegd.
In de praktijk is er erg weinig aan banden gelegd. De Autoriteit Persoonsgegevens zegt daarover hier het volgende: "Een fabrikant of aanbieder moet om toestemming vragen. Gaat u ermee akkoord dat het bedrijf uw persoonsgegevens verzamelt via uw tv of settopbox? Geeft u geen toestemming? Dan mag het bedrijf u niet benaderen met persoonlijke kijkaanbiedingen en advertenties". Uit het verhaal van Gamers Nexus blijkt dat het ondoenlijk is voor de gemiddelde gebruiker om alle gebruiksvoorwaarden door te nemen. Daardoor gaat in de praktijk iedereen gewoon akkoord met het verzamelen van deze gegevens. Verder staat het een fabrikant van dergelijke toestellen vrij om, wanneer de gebruiker niet akkoord gaat met de gegeven gebruiksvoorwaarden, het toestel niet te laten werken of zelfs maar te laten opstarten.

Daarnaast, en dat blijkt ook uit het verhaal van Gamers Nexus, worden in het geval van LG ook gewoon gegevens geregistreerd en opgeslagen van personen/gebruikers/derden die geen toestemming hebben gegeven. Dit bijvoorbeeld wanneer zijn een gesprek voeren in een aanliggende ruimte of wanneer ze gebruik maken van een apparaat dat actief is op hetzelfde (WiFi) netwerk. Ook maakt het, zo blijkt uit het verhaal van Gamers Nexus, niet uit of het toestel van LG daadwerkelijk aan staat of in een standby stand staat. Problematisch is ook dat de ACR beelden opslaat en registreert. Een LG toestel dat gebruikt wordt in b.v. een ziekenhuis, een tandartsenpraktijk of in een omgeving waarin vertrouwelijke bedrijfsgegevens worden besproken zou daarom, al was het enkel uit voorzorg, onmiddellijk moeten worden verwijderd. Verder is het risico op een gehackt toestel in dergelijke omgevingen onnodig groot.

In dit geval heeft Gamers Nexus LG onderzocht en hoe het zit bij andere merken/fabrikanten blijft (vooralsnog?) onduidelijk. Er is op dit moment geen reden om aan te nemen dat het 'beter' zou zijn.

  • MAX3400
  • Registratie: Mei 2003
  • Laatst online: 08-09 11:29

MAX3400

XBL: OctagonQontrol

Wim1147 schreef op maandag 7 september 2026 @ 03:05:
...zelfs de gesprekken van gebruikers en hun directe omgeving registreren wanneer het toestel niet is verbonden met het internet.
Even advocaat van de mindere duivel: als er door geen connnectiviteit niets naar buiten lekt, wat is het probleem dan? Firmware-updates kan je bij (alle?) TV's nog steeds via USB doen dus daar is ook geen internet voor nodig.

Er zijn genoeg mensen (op Tweakers en elders) die aparte manieren hebben om streaming media te consumeren zoals een smartphone casten, een Plex, een AppleTV, console etc. Het euvel uit de startpost (hoe privacy-schendend ook) is dus eigenlijk alleen van toepassing op mensen die alles maar via het internet op de TV met de ingebouwde apps/stores doen.

En ongetwijfeld loop ik achter maar ook Linus heeft (al dan niet met gezamenlijke data) in Je smart-tv bespioneert je een aantal zaken besproken die niet / nauwelijks door de consument opgelost kunnen worden en "we" zijn dus allemaal advertentiemateriaal voor (bijna) alle TV-fabrikanten.

Mijn advertenties!!! | Mijn antwoorden zijn vaak niet snowflake-proof


  • Gulli
  • Registratie: Oktober 2001
  • Laatst online: 07-09 13:40

Gulli

100% Unwiderstehlich

MAX3400 schreef op maandag 7 september 2026 @ 13:25:
[...]

Het euvel uit de startpost (hoe privacy-schendend ook) is dus eigenlijk alleen van toepassing op mensen die alles maar via het internet op de TV met de ingebouwde apps/stores doen.
Ofwel 99% van de gebruikers. Ga er niet vanuit dat Tweakers de norm zijn, zeker niet.

Connaisseur des femmes


  • BartStaal98
  • Registratie: November 2022
  • Laatst online: 13:01
vrieske schreef op maandag 7 september 2026 @ 13:21:
Ik heb zelf de lg domeinen al een tijd (enkele jaren)in pihole banlijst staan. Daarmee breekt wel de lg store enzo en de apps die je geïnstalleerd hebt staan moet je van hopen dat het blijft werken. Maar goed ik heb alleen jellyfin en youtube app geïnstalleerd.
Ik heb zelf ook een jellyfin server die ik op mijn LG TV via Litefin aanspreek. Daarvoor heb ik de TV in LG dev mode gezet en via WebOSBrew (Homebrew) litefin geinstalleerd. Zo nu en dan verleng ik die dev mode token (is 1000 uur geldig).

Ik neem aan dat wanneer ik de lg domeinen blokker op AdGuard dat deze litefin sideload ook breekt? Dan wel nu, dan wel over max 1000 uur? Weet jij tot hoe ver die dns-block gaat?

  • Wim1147
  • Registratie: April 2023
  • Laatst online: 13:20
MAX3400 schreef op maandag 7 september 2026 @ 13:25:
[...]Even advocaat van de mindere duivel: als er door geen connnectiviteit niets naar buiten lekt, wat is het probleem dan? Firmware-updates kan je bij (alle?) TV's nog steeds via USB doen dus daar is ook geen internet voor nodig.
Het gaat hier om een televisietoestel, een apparaat dat bedoeld is om televisieuitzendingen en films e.d. op te bekijken. Meer dan een scherm met een set luidsprekers hoeft het niet te zijn. Anders gezegd: het registreren van allerlei gegevens van de gebruiker(s) en de omgeving van de gebruiker(s) heeft niets te maken met de functionaliteit van zo'n apparaat. Het probleem is het registreren zelf en pas in de tweede plaats het 'lekken' naar buiten. Andere problemen met het registreren ervan is dat het toestel zelf nog gewoon kan doorgaan met het opbouwen een 'fingerprint'. Uit het verhaal van Gamers Nexus blijkt ook dat de ACR van LG gewoon data blijft registreren.

Het is voor de gemiddelde gebruiker vrijwel onmogelijk na te gaan of een dergelijk LG toestel al geroot of gehackt is (van buitenaf). Volgens Gamers Nexus is dat een risico. Het uitvoeren van een firmware update is mogelijk om dezelfde reden riskant. Het maakt dan niet uit of deze update gedaan via usb of online. Er is een risico op het installeren van een 'backdoor' of het veranderen van bestaande instellingen bij dergelijke toestellen door een dergelijke update.

  • MattiVM
  • Registratie: Mei 2017
  • Laatst online: 23:39
MAX3400 schreef op maandag 7 september 2026 @ 13:25:
[...]
Er zijn genoeg mensen (op Tweakers en elders) die aparte manieren hebben om streaming media te consumeren zoals een smartphone casten, een Plex, een AppleTV, console etc. Het euvel uit de startpost (hoe privacy-schendend ook) is dus eigenlijk alleen van toepassing op mensen die alles maar via het internet op de TV met de ingebouwde apps/stores doen.
Hoe ga je casten naar een TV als je deze niet gaat connecteren met het internet? Dan zou je deze al moeten verbinden met je router of wat dan ook, maar blokkeren dat deze mag verbinden met het internet, enkel met LAN. Tweakers kunnen dit misschien doen, maar vraag dit niet aan de gemiddelde gebruiker om dit te doen.

En daarbij, het is net de gemiddelde gebruiker die waarschijnlijk nog niet eens weet hoe "smart" en dus "creepy" hun TV is of kan zijn. Die gebruiken dus wel de apps op de TV. Ik doe dit ook uit gemak, eerlijk. Ik ga niet nog eens geld neerleggen voor een apart toestel dat hetzelfde doet als de smart functies van mijn TV. En wees maar zeker dat die streaming doosjes of sticks ook alles behalve heilig en eerlijk zijn.

Daarnaast is "ACR" (Automatic Content Recognition) niet enkel en alleen van toepassing op het smart gedeelte van de TV. Elk beeld dat binnenkomt via HDMI kan ook bekeken worden door ACR. Je bent dus op geen enkele manier meer "veilig".

  • Dalitso
  • Registratie: Augustus 2021
  • Laatst online: 07-09 15:54
Wat niet super bekend lijkt te zijn, is dat veel LG TVs te rooten zijn, zeker als je firmware updates uit hebt gezet of de TV nooit met internet hebt verbonden. Je kan op https://cani.rootmy.tv zien of je TV rootable is. Ook is er vrij actieve community op Discord: https://openlgtv.github.io/ . Er is een tijdje een nieuwe exploit uitgekomen waar veel TVs überhaupt nog geen update voor hebben gekregen.

LG TVs zijn volledige ARM Linux systemen gebaseerd op wat ooit Palm's webOS was, die ook vandaag nog open source releases heeft. Draait Wayland om de user interface te renderen, die vervolgens in hardware op de video output wordt gecomposite. Veel van de UI apps zijn Javascript gebaseerd, waarbij de code unobfuscated op het filesystem staat.

Ik geloof wel dat als je ACR in de settings uit zet, het daadwerkelijk niet naar LG wordt opgestuurd. Ik denk alleen niet dat er informed consent gegeven wordt: mensen beseffen zich niet waar ze toestemming voor geven. Daarmee overtreed LG mogelijk de AVG.

Ik heb vandaag Claude eens gevraagd om voor webOS 3.5 en 24 te kijken hoe het zit met automatic content recognition op basis van een filesystem dump. Dat levert een hoop informatie op, die ik nog niet zelf heb doorgenomen. Neem het daarom met een flinke korrel zout, maar het kan wel informatief zijn. Ik weet ook niet 100% zeker dat ik van de webOS 24 TV het volledig filesystem te pakken heb, wat er misschien zorgt dat ik een aantal telemetry-paden gemist heb die op de webOS 3.5 TV wel aanwezig zijn. Als je nog iets specifieks wilt weten, vraag gerust.

Het eerste blok is webOS 24 van een vrij moderne TV uit 2024. Het tweede blok is webOS 3.5 van een TV uit 2017. Het laatste blok is een vergelijking tussen de twee. Het is Markdown, dus het beste te lezen als je het kopieert naar een renderer daarvan, Obsidian bijvoorbeeld.

Gesplit over twee posts vanwege de lengte-limiet op Tweakers.
# ACR and backend telemetry components in the webOS 24 root filesystem

## Subject

An extracted root filesystem, with all mounts, taken from a rooted LG television.

| | |
| --- | --- |
| Model | `55NANO82T6B.BEUSLJP` — NANO82 series, 55", LCD/NanoCell |
| Model year | 2024 (`manufactureYear: 2024`, platform code `W24P`, product code `webOSTV 24`) |
| Panel / tuner | UD (2160p) at 60 Hz, CEDS interface; DVB (`sysType: DVB`), tuner present |
| SoC / memory | `K8LPN2` (machine `k8lpn2`), 1.5 GB DDR |
| OS | webOS TV 24; starfish release `Rockhopper release 10.2.2-5901 (ponytail-paparoa)`; platform version `10.2.2` |
| Firmware | `33.22.86`; bootloader `9.00.89/9.00.89` |
| Service country | NL / NLD; UI locale `nl-NL`, formats and NLP `en-GB`; language group `EU` |
| SDP region | EIC (LG's Europe/rest-of-world region), environment `Production` |
| Channel map | `NL-webOS-6.4.0-MR`, version `202609030035` |
| Serial | `50~~~~~~~~~~~~~~~[REDACTED 10 digits]` (full value in `var-18/preferences/configd_db.json`, key `tv.model`) |

The update server advertises `33.31.61` as the current official NL build for this model
(`mnt-6/lg/cmn_data/sdp/sdx/detailconfig.json`, `nsu` block), so the image is one or more
releases behind the shipping firmware. Developer mode is not enabled
(`var-18/luna/preferences/devmode_enabled` is empty).

Snapshot age: the newest file written by the TV itself is
`mnt-6/lg/cmn_data/acr/data/power_off_info`, timestamped 2026-09-04 16:48 UTC, which is the last
power-off. Analysis was performed 2026-09-07. Runtime state described below is therefore the
state at that last power-off, not at first boot.

Sources for the table: `etc/starfish-release`, `var-18/preferences/configd_db.json`
(`tv.model`, `tv.nyx`, `tv.hw`), `mnt-6/lg/cmn_data/var/webos-profile/device_selection.json`,
`var-18/luna/preferences/localeInfo`, `mnt-6/lg/cmn_data/pbs/pbs_config.json`.

## Scope and method

Static inspection only. Paths below are relative to the directory containing this file.
`usr-2/` is the mount holding `/usr`, `mnt-6/` holds `/mnt/lg`, `var-18/` holds `/var`, and
`etc/` holds `/etc`. Where a component's on-device path matters it is given in absolute form as
the binary itself refers to it.

The approach was: locate services and packages by name, read their Luna manifests and startup
activities, extract strings from the ELF binaries, and read the runtime state files the
components leave in `/mnt/lg/cmn_data`. Nothing was executed and no traffic was captured. Claims
about what a binary sends are drawn from format strings, URL fragments and symbol names, so
field lists are indicative rather than an observed wire format. Where plaintext source was
available (QML, JavaScript, Python, shell) that is stated, and those parts are exact.

Identifiers belonging to this device or to third parties are redacted in place, marked
`~~~~~~~~~~~~~~~[REDACTED …]`, with enough structure left to show the shape of the value. Three occur: the
BSSIDs of two neighbouring access points in §1.5, the device identifier in §6.1, and the ad
server session token in §2.1. The device serial in the table above is partially masked. Nothing
else in this report is specific to one unit.

---

## 1. Automatic Content Recognition

### 1.1 The service

`usr-2/palm/services/com.webos.service.acr/services.json` states the purpose directly:

```json
{
"id": "com.webos.service.acr",
"description": "Automatic Content Recognition",
"services": [ { "name": "com.webos.service.acr" } ]
}
```

The package manifest (`usr-2/palm/packages/com.webos.service.acr/packageinfo.json`) titles it
"ACR Service", version 0.0.1.

Files that make it up:

| Path | Size | Role |
| --- | ---: | --- |
| `usr-2/sbin/acr2` | 558 684 | The daemon. Capture plumbing and Luna API. |
| `usr-2/lib/libalphonsosolution.so.1.0.0` | 87 472 | Adapter between `acr2` and the vendor SDK. |
| `usr-2/lib/libas.so.3.0.93` | 2 565 924 | Alphonso ACR SDK. Fingerprinting and network I/O. |
| `usr-2/lib/libalphonsoadoverlay.so.1.0.0` | 50 608 | Same adapter pattern for the ad-overlay service. |
| `usr-2/lib/libvtcapture.so.1.0.0` | — | Video/screen capture (`screen-capture-webos` 1.0.0-56). |
| `usr-2/share/acr/acr.a.2.1.4.db.zero.mp3` | 295 184 | Shipped fingerprint database, despite the `.mp3` extension. |
| `usr-2/palm/applications/com.webos.app.acrcomponent` | — | Hidden overlay WebView. |
| `usr-2/palm/applications/com.webos.app.acroverlay` | — | Same, bound to live TV. |
| `usr-2/palm/applications/com.webos.app.acrhdmi{1..4}` | — | Same, one per HDMI input. |
| `ROOT/opt/webos/tests/acr2/gtest_acr2` | — | Unit tests, left in the image. |
| `etc/pmlog.d/acr.conf` | — | Log context configuration. |

`acr2` links `libasound.so.2` and `libvtcapture.so.1` alongside `libluna-service2`,
`libcrypto.so.3` and `libjsoncpp`.

### 1.2 What it captures

Symbol and string extraction from `acr2` shows two capture paths running in their own threads.

Audio: classes `capture::AudioCapture` and `capture::AlsaAudioWrapper`, wrapping ALSA
(`PcmOpen`, `PcmHwParamsSetRateNear`, `PcmHwParamsSetChannels`, `PcmReadi`), with a recovery
loop that logs `[AudioCapture] Audio Capture Recovery count[%d]`. This is a tap on the TV's
own audio mixdown, not a microphone.

Video: classes `capture::VideoCapture`, `capture::ImageConverter`, `capture::CaptureBuff`,
`capture::CaptureDelegate`, plus a string `DaiFastCapture`. `libvtcapture` is the LG
`screen-capture-webos` library, whose API strings (`create vt capture handle`,
`process vt capture called by %s`, `vtHistogram`) describe frame grabs off the video pipeline.
DAI most plausibly stands for dynamic ad insertion, which would make the fast-capture path an
ad-break detector, but I did not confirm that.

Configuration keys present in the binary include `capture_method`, `whitelist_method`,
`colorInversion`, `acr_config_format_ver`, `firmware_version`, `webos_version`.

### 1.3 Vendor engine and loading

`acr2` contains a `core::SolutionLoader` that resolves a vendor engine at runtime from
`/mnt/lg/cmn_data/acr/lib/`, passing it `WebOSVersion()` and `FirmwareVersion()`. That directory
is empty on this device, so the preinstalled `libalphonsosolution.so` and `libas.so` are what is
in use. `libalphonsosolution.so` exports `CreateSolution` and implements
`solution::alphonso::AlphonsoSolution` and `AlphonsoClient`.

`libas.so.3.0.93` retains its build path, which names the vendor and the LG port:

```
/mnt/alpha/acr-sdk/sdk-build/git-lg-webos-24/acr-sdk/common/audio/AudioHdlr.cpp
/mnt/alpha/acr-sdk/sdk-build/git-lg-webos-24/acr-sdk/common/as-client/ASClientOptout.cpp
/mnt/alpha/acr-sdk/sdk-build/git-lg-webos-24/acr-sdk/common/utils/UtilsReadWifiProperties.cpp
```

The audio handler is a state machine with states for `PreBuffering`, `Running`, `Sleeping`,
`RunningPO`, `SleepingPO` and `InitedLivetvExpress`, plus `SplitACR.cpp` and constants
`ACR_TYPE_SPLIT`, `ACR_SHIFT_TYPE_93`, `ACR_SHIFT_TYPE_186`. "PO" appears to mean power-off,
given `AudioHdlrPOSleepTimerCB` and `AudioHdlrPOPrimeTimeTimerCB` — a scheduled, prime-time-
weighted wake pattern. Source types are enumerated as
`ASAPI_SOURCE_LOCAL_AUDIO_TYPE_{PLATFORM,EXTERNAL,MIC}`, so the SDK has a microphone input mode
compiled in; nothing in `acr2` selects it, and `acr2` only opens ALSA capture on the platform
mixdown.

On a match, `AlphonsoClient` logs the identifiers it received:

```
[AlphonsoClient] ContentResult : tms program id : %s, tms station id : %s
[AlphonsoClient] AlphonsoMatchCB: json_info: %s
```

TMS IDs are Gracenote's content and station identifiers, which is what ties a fingerprint back
to a named programme and channel.

### 1.4 Where fingerprints go

Hostnames in `libas.so.3.0.93`:

- `prov-lg.alphonso.tv` (`ASAPI_PROV_SERVER`) — provisioning; the ACR server address is then
supplied dynamically (`ASAPI_ACR_SERVER`, `AS_ACR_SERVER_UPDATE`).
- `eulacheck.alphonso.tv` — consent check.

API paths in the same binary:

```
/audio/fingerprint /user /user/location
/user/lookups /user/timed-lookups /user/appsource
/recommendation /recommendation/info /bl/config
/device/config /device/clock /countryList
/latestVersion /log/tar /sdk_debug/stats
recommendation/v1/ott recommendation/v1/ott_feedback
```

Query parameters seen as fragments: `alp_uid=`, `device_id=`, `api_key=`, `zipcode=`,
`ipaddr=`, `app_version_code=`, `app_version_name=`, and log strings printing
`longitude:` and `zipcode:` next to each other. `/user/appsource` alongside
`ASAPI_SOURCE_LOCATION_{LOCAL,REMOTE}` suggests the SDK also reports which input or app the
audio came from.

### 1.5 Wi-Fi scanning for location

`libas.so.3.0.93` contains `UtilsReadWifiProperties.cpp`, a dedicated
`ASUtilsReadWifiPropertiesThread`, a `startScan()` and `processUpdateWifiScanInfo()`, a
comparator `compareBySignalStrength`, and these strings:

```
Wifi Scanning Start
Wifi Scanning Stop
Wifi Scanning disabled
Recvd enable_wifi_scan:
LocationClient() with lat/long and wifiScanOutput.
Empty wifiScanJsonOutput:
```

`acr2` has the matching `interface::Wifi` class with `OnFindNetworks` and writes the result to
disk. The file is present on this device:

`mnt-6/lg/cmn_data/acr/data/wifi_network_info`

```json
[{"mac_address":"[REDACTED MAC]","signal_strength":"-57"},
{"mac_address":"[REDACTED MAC]","signal_strength":"-63"}]
```

Those are neighbouring access points, not the TV's own radio. A BSSID list with signal strengths
is the standard input to a Wi-Fi geolocation lookup, which resolves to a street-level position
without GPS and without the user entering an address. The scan is enabled server-side
(`Recvd enable_wifi_scan:`), so it is not governed by a setting in the TV's menus.

### 1.6 Runtime state and current status

`mnt-6/lg/cmn_data/acr/data/`:

| File | Contents |
| --- | --- |
| `optin` | `optin` |
| `first_optout` | `first_optout` |
| `eula_allowed` | `allowed` |
| `sdp_server` | `Production` |
| `service_country` | `NL` |
| `power_off_info` | `{"time_stamp":1788540517}` |
| `wifi_network_info` | see above |

`var-18/luna/preferences/option` contains `"livePlus": "on"`. Live Plus is the menu name for
this feature. ACR is therefore enabled on this device, and the opt-in is recorded both in the
Luna settings store and in the ACR service's own state directory.

Factory defaults in `etc/palm/defaultSettings.json` are the opposite: `acrAllowed`, `acrOnAllowed`,
`acrAdAllowed` and `acrGdprAllowed` are all `false`. The enabled state came from setup or from
the EULA acceptance flow, not from the shipped defaults.

Vendor logging is disabled. `mnt-6/lg/cmn_data/acr/alphonso/log4cplus.properties`:

```
log4cplus.rootLogger=ERROR, R

log4cplus.appender.R=log4cplus::NullAppender
```

Everything at ERROR and below is routed to a null appender. A debug variant exists at
`usr-2/share/acr/log4cplus-debug.properties`, gated on `/var/luna/preferences/alphonso_debug`.

### 1.7 Startup

`etc/palm/activities/com.webos.service.acr/activity-com.webos.service.acr.start.json` registers
`luna://com.webos.service.acr/startAcr` with `{"reason":"normal"}`, triggered on
`com.webos.bootManager/getBootStatus` reaching `rest-boot-done`. So the service starts on every
boot, not on demand.

`acr2` also registers activities that restart it when the advertising identifier changes
(`"name": "ccpa changed"`, watching `com.webos.service.admanager/getAdid` for `IFA` changes) and
on network connect, EULA acceptance, store-mode change, power on and pre-power-off. Its own log
messages enumerate these: "ACR service as dynamic for connection network", "for eula allowed",
"for live plus menu", "for power on", "for prepare power off", "for store mode".

`usr-2/share/luna-service2/client-permissions.d/com.webos.service.acr.perm.json` grants the
service, and its sync and async client handles, `["all"]` — unrestricted access to the Luna bus.

### 1.8 The overlay apps

`com.webos.app.acrcomponent`, `com.webos.app.acroverlay` and `com.webos.app.acrhdmi1` through
`acrhdmi4` are near-identical hidden web apps, all titled "LivePlus", all placed on a window
layer named `acrLayer` owned by live TV or by the external-input app, with `"visible": false`
and `"class": {"hidden": true}`.

`index.html` sets a zero-size input region and `KeyMaskNone`, so the app is present but takes no
input, then loads `present_frm.html` into an iframe. `present_frm.html` is four lines of logic:

```js
var params = JSON.parse(window.PalmSystem.launchParams);
if (params.contentTarget != undefined) {
window.location = params.contentTarget;
}
```

The container navigates to whatever URL the service passes in `contentTarget`, and re-navigates
on `webOSRelaunch`. The rendered content is entirely server-controlled. The per-HDMI variants
mean overlays can be drawn over an external device's picture, not only over the tuner.

---

## 2. Advertising services

### 2.1 admanager

`usr-2/sbin/admanager` (293 428 bytes), service `com.webos.service.admanager`, described in its
manifest as "Advertisement Service Manager".

Endpoint host in the binary: `info.lgsmartad.com`. Paths:

```
/rest/json/v1.0/req
/rest/json/v1.0/baseinfo
/rest/json/v1.0/appinfo
/rest/xml/v1.0/api/DNSInfo
/rest/xml/v1.0/api/TNC?TNC=
```

The live cookie jar `mnt-6/lg/cmn_data/admanager/cookie/ad_cookie` shows the regional host this
device actually talks to:

```
#HttpOnly_.nl.ad.lgsmartad.com TRUE /rest FALSE 0 JSESSIONID [REDACTED 32 hex chars]
```

The class `CIFAdService` owns the advertising identifier. Methods include `getAdRequestInfo`,
`requestCampaignInfo`, `requestContextIndex`, `requestBaseAsset`, `sendAssetMsg`, `assetClicked`,
`reqNormalLog`, `startDownloadUrl`, `createSDKContext` and `launchCMPApp`. Request parameters
`&ifa=` and `&ifa_type=` are built inline, and the IFA is fetched from the Security Manager
(`Failed to get IFA from Security Manager`). Reset is handled by `MSG_AD_RESET_IFA`, which emits
the telemetry event `NL_ADMAN_IFA_RST`.

`mnt-6/lg/cmn_data/admanager/cache/` holds around two dozen downloaded creatives, named after
their source URLs on `ngfts.lge.com` under `biz_code=CMS&func_code=CMS_ASSET`.

Startup: `etc/palm/activities/com.webos.service.admanager/` triggers `admanager/start` when
`com.webos.service.connectionmanager/getstatus` reports `isInternetConnectionAvailable: true`.
`etc/init/admanager.conf` pre-creates the cache directory at boot.

### 2.2 adoverlay

`usr-2/sbin/adoverlay-service` (452 176 bytes), service `com.webos.service.adoverlay`, "Ad
Overlay Service". It follows the ACR design exactly: a vendor engine directory at
`/mnt/lg/cmn_data/adoverlay/lib/`, an Alphonso adapter (`libalphonsoadoverlay.so`), its own
`acr.a.2.1.4.db`-equivalent fingerprint DB at `usr-2/share/adoverlay/adoverlay.a.2.1.4.db.zero.mp3`,
and a state directory `mnt-6/lg/cmn_data/adoverlay/data/` containing `eula_allowed: allowed`,
`sdp_server: Production`, `service_country: NL`.

It carries the check `[ACR] ACR Solution is not Alphonso.`, confirming it is content-recognition
driven. It also reads `/mnt/lg/cmn_data/shopping/stored_data.json` and requests HTTP headers via
`getHttpHeaderForServiceRequest`, i.e. it authenticates to LG's SDP like the other services.

Front ends: `com.webos.app.adoverlay`, `com.webos.app.adoverlayex`, and
`com.webos.app.adhdmi{1..4}` — the same per-input pattern as the ACR overlays.

### 2.3 videoads

`usr-2/palm/applications/com.webos.app.videoads/app.js` is unminified and readable. It is a
screensaver-type app (`"defaultWindowType": "screenSaver"`, `"requiredPermissions": ["all"]`)
that builds its URL from a regional code:

```js
const config = { baseHost: "videoads.lgtvcommon.com", isNextSDP: true, isProduction: true, ricCode: "" };

const buildURL = () => {
const env = config.isProduction ? "" : "dev-";
const region = config.ricCode.toLowerCase() || "aic";
return `https://${env}${region}.${config.baseHost}/`;
};
```

The region map sends KOR/AUS/JPN/IND/SGP/NZL/TWN to KIC, the Americas to AIC, and everything
else, including NL, to EIC. So this device loads `https://eic.videoads.lgtvcommon.com/`.
Production vs. staging is decided by inspecting the `HOST` header returned by
`com.webos.service.sdx/getHttpHeaderForServiceRequest`.

### 2.4 Other ad-related paths

- `mnt-6/lg/cmn_data/adlogservice/data/`
- `usr-2/palm/license/XAD`
- `etc/pmlog.d/admanager.conf`, `etc/pmlog.d/adoverlay-service.conf`
- `ROOT/opt/webos/tests/admanager/gtest_admanager`

---

## 3. Viewing-history reporting

### 3.1 PersonalDataLogger

`usr-2/palm/applications/com.webos.app.inputcommon/qml/Interfaces/ChannelInfoInterfaces/PersonalDataLogger.qml`
is plaintext QML and is the most legible telemetry sender in the image. It fires on channel
change and POSTs through the SDX transport to the SDP service `ibis_stat_secure` at
`sdp/livetvwatch.json`.

Tuner body, built verbatim in `sendPersonalLogTv`:

```
chan_name, chan_code, prev_chan_code, device_src_idx, dtv_standard_type,
accept_flag, zipcode, timezone, user_id, channel_change
```

Set-top-box body, from `sendPersonalLogStb`, adds `content_id` and `from_where`. The
`from_where` values are declared at the top of the file:

```qml
readonly property int fromWhereAcr: 10
readonly property int fromWhereScd: 11
readonly property int fromWhereUei: 12
```

`checkSendLogStb` implements the priority ACR > UEI > SCD. This is the joining point between the
two halves of this report: ACR identifies what is playing on a connected set-top box, and the
result is reported to LG as a channel-viewing record with the same schema used for the internal
tuner.

Consent is checked per source before sending — `watchFlag` for RF, `ipWatchFlag` for IP
channels, `stbAcrWatchFlag`, `stbScdWatchFlag`, `stbUeiWatchFlag` for the STB paths — and the
server can independently switch each off in its reply via `activation_flag`, `ip_activation_flag`,
`stb_acr_activation_flag` and so on.

Sends are deliberately jittered:

```qml
requestTimer.interval = Math.floor((Math.random() * 10000) + 1) + minTime; // minTime = 10000
```

10 to 20 seconds after the channel change. A fixed delay would make the report trivially
correlatable with the user action; the randomisation removes that.

### 3.2 pbs

`usr-2/sbin/pbs` supplies the identity and the consent flags that `PersonalDataLogger` reads via
`getAuthenticatedData`. Its `UniqueID` class chains `getMacAddress()`, `encryptMacAddr()` and
`convertSHA512()`. The `user_id` in every viewing record is therefore a SHA-512 derived from the
TV's MAC address: stable for the life of the device, resettable only in the sense that
`UniqueID::reset()` exists.

`pbs` also handles `X-Device-Eula` headers, `isZipcodeMandatory()`, and talks to `ibis_secure`.

`mnt-6/lg/cmn_data/pbs/pbs_config.json` on this device:

```json
{ "watchFlag": true, "ipWatchFlag": false, "stbAcrWatchFlag": false,
"stbScdWatchFlag": false, "stbUeiWatchFlag": false,
"channelplus": true, "generalTerms": true, "pbsAuth": true,
"country": "NLD", "channelMapId": "NL-webOS-6.4.0-MR" }
```

Tuner channel-change reporting is on. The STB detection paths, including the ACR one, are off
server-side even though the ACR service itself is running and opted in.

---

## 4. The general analytics pipeline

Events are emitted as key/value log lines with a `NL_` prefix, collected by `rdxd`, and uploaded
by `uploadd` to LG's RDX server. Grepping the binaries, libraries, apps and configs yields
**584 distinct `NL_*` event codes**.

### 4.1 Emission

Producers call `PmLogCtl logkv`. `etc/palm/service-logger/rules/extInput.py` shows the pattern
end to end — it queries `com.webos.service.eim/getAllInputStatus`, walks every connected device,
and emits an inventory:

```python
logData['dev_list'] = devList
log = json.dumps(logData, ensure_ascii = False)
cmd = ['PmLogCtl', 'logkv', 'EIM', 'info', 'NL_EIM_INPUTLIST', log]
subprocess.run(cmd)
```

Each record carries the device `name`, `type`, `label` (from `labelName`, `serviceName` or
`brandName` of the URCU/SIMPLINK data) and `id`. `rule.json` schedules this monthly.

Sibling collectors in the same directory: `getGameDeviceInfo.py` (triggered on picture-mode or
aspect-ratio change while an HDMI input is active), `getScreenInfo.py`, `getFirstUseTVInfo.py`,
`getFirstUseAppInfo.py`, `getBatteryCyInfo.py`. The scheduler is `usr-2/sbin/service-logger`,
configured by `etc/palm/service-logger-conf.json` and backed by a MojoDB kind
`com.webos.service.logger.activity:1`.

### 4.2 Collection

`usr-2/sbin/rdxd`, configured by `etc/rdxd.conf` with `AutoUpload=true`. Report types are
registered in `etc/rdxd.d/`:

```json
{ "type":"analytic", "handlerURL":"com.palm.uploadd/uploadAnalyticsReport" }
{ "type":"crash", "handlerURL":"com.palm.uploadd/uploadCrashReport" }
```

It respects two gates, both visible as strings in the binary: "EULA has not accepted yet,
analytics reports will not be created" and "Devmode is enabled, analytics reports will not be
generated".

Crash reports are bundled with context produced by `usr-2/share/rdxd/make_sysinfo.sh`, which is
a plain shell script. It captures `/proc/cpuinfo`, the eMMC `manfid`/`oemid`/`serial`,
`/proc/mounts`, `/etc/version`, then `uptime`, `df -h`, `ps aux`, `date -R`,
`ls -l /var/luna/preferences` and `ifconfig`, then queries the bus for attached storage devices,
all input statuses, the last ten power on/off events, connection status and the running app list.

### 4.3 Upload

`usr-2/sbin/uploadd`, configured by `etc/uploadd.conf`:

```ini
[server=rdx]
AnalyticsLogURL=log/normal
CrashLogURL=log/crash

[upload]
MaxUploadBytes=2097152
```

It will not send unless the EULA is accepted, an SDX server is available, and SDP/SDX
authentication has succeeded — each is a distinct refusal string in the binary. Failed uploads
retry five times with a minimum hour between attempts. Sent files move to
`/var/spool/uploadd/uploaded`. First-use marker: `mnt-6/lg/cmn_data/uploadd/initial_date.txt`
contains `202004`.

The destination is the `rdx_secure` SDP service, `rdx2.<region>lgsdp.com`, with a separate
developer-log route to `rdl.lgtvcommon.com`.

### 4.4 Event coverage

A sample of the 584 codes, chosen to show breadth rather than to be exhaustive:

```
NL_ACR_OFF_REASON NL_ADOVERLAY_OFF_REASON NL_ADMAN_REQ / _IMP / _CLK
NL_ADMAN_IFA_RST NL_AD_CLICK NL_AD_SWITCH_MANUAL
NL_CHANNEL_CHANGE NL_CHANNELS_IN NL_BROADCAST_CHANNEL_COUNT
NL_BROADCAST_WATCH_CHANNELSOURCE / _RESOLUTION / _SLINGTV
NL_APP_LAUNCH NL_APP_INSTALLED NL_APP_REMOVED
NL_LAUNCH_APP NL_CLOSE_APP NL_INPUT_APPHISTORY
NL_ACTIVATE_VOICE NL_ACTIVATE_SEARCH NL_CHATBOT_VOICE_RESULT
NL_FARVOICE_ACTIVATION / _TRIGGER / _ALEXA / _DANGBEI
NL_EIM_INPUTLIST NL_EULA_CHANGED NL_ACCESSIBILITY_CHANGED
NL_DVR_WATCHNRECORD NL_GAME_OPTIMIZER_CHANGE NL_CAMERA_APP_INFO
```

Some codes double as on-disk cache filenames, e.g. `mnt-6/lg/cmn_data/NL_VIDEO_ALL_DIM_ASPECT_RATIO_HISTORY_CACHE`.

---

## 5. SDX: the shared transport

`usr-2/sbin/sdx` (792 484 bytes), service `com.webos.service.sdx`, is the HTTPS client every
other component posts through. Callers pass a logical `serviceName` plus a path and method, and
`sdx` resolves the hostname, attaches authentication headers and performs the request. Its two
public helpers, seen throughout the apps, are `send` and `getHttpHeaderForServiceRequest`.

The routing table ships at `usr-2/palm/sdx/server_addr_version.conf` and is updated in place at
`mnt-6/lg/cmn_data/sdp/sdx/server_addr_version.conf` (37 entries on this device). In both files
the LG-operated hosts appear as the literal `nextlgsdp.com`, prefixed at runtime by region.
Entries relevant here:

| serviceName | domain | base path |
| --- | --- | --- |
| `sdp_logging` | `nextlgsdp.com` | `logging/10.0.0/` |
| `ibis_secure` | `ibs.nextlgsdp.com` | `ibs/10.1.0/` |
| `ibis_stat_secure` | `ibsstat.nextlgsdp.com` | `ibs/10.0.0/` |
| `rdx_secure` | `rdx2.nextlgsdp.com` | `rdx/9.0.0/` |
| `rdxdev_secure` | `rdl.lgtvcommon.com` | `devlog/nextsdp/v1.0/` |
| `cdpbeacon_secure` | `cdpbeacon.lgtvcommon.com` | `api/v2/beacon/` |
| `nudge_secure`, `nudge_log_secure` | `nudge.lgtvcommon.com` | `nudge/nextsdp/` |
| `recommend_secure`, `tlamp_secure` | `recommend.lgtvcommon.com` | `recommend/…`, `tlamp/…` |
| `cpv_secure` | `pnv.lgtvcommon.com` | `rest/csi/` |
| `homeprv_secure` | `homeprv.lgtvcommon.com` | `nextsdp/homeprv/` |
| `service_setting_secure` | `wiseconfig.lgtvcommon.com` | `nextsdp/smartConfig/` |
| `cpauth_secure` | `cpauth.lgtvcommon.com` | `auth/nextsdp/v1.0/` |

`sdx` also exposes `getRdxServer` and `getRdxServerUrl` to the bus, which is how `uploadd`
discovers where to post.

Because everything funnels through one daemon, the per-component hostnames above are not
individually resolvable from a network capture without also reading this table.

---

## 6. Behavioural profiling on-device

### 6.1 user-context-manager and user-intent-manager

`usr-2/sbin/user-context-manager` and `usr-2/sbin/user-intent-manager` maintain ranked usage
profiles in MojoDB. Their `QueryProcessor` builds `RankInfo` lists by genre, keyword, intent
type and channel (`makeRankInfoGenreList`, `makeRankInfoKeywordList`,
`makeRankInfoIntentTypeList`, `makeRankInfoYChannelList`), and expose `getHistory`, `getRank`,
`getSubRank` and `getCategorizedRank` on the bus.

The method name worth flagging is `DBHandler::findHistoryInfoForServer` in
`user-context-manager` — a distinct query path from `findHistoryInfo`, i.e. history shaped for
transmission rather than for local use. There is also a monthly summary feature
(`displayMonthlyReport`) whose user-facing strings are in the binary: "Last month, you watched TV
for an average of about {hour} hours per day and used {app name} the most."

`var-18/preferences/com.webos.service.usercontextmanager` currently holds
`1672531310NL250[REDACTED 10 digits]com.webos.app.home1756457284` — a timestamp, the device serial, the
most-used app, and a second timestamp.

### 6.2 nudge

`usr-2/sbin/nudge` reads those profiles (`GetUCMHistory`, `GetUCMChannelRank`) and keeps its own
kind `com.webos.service.nudge.history:1`. Rules are JSON in `mnt-6/lg/cmn_data/nudge/`, one per
prompt: `nu_ch_watch_tv_n_times.json`, `nu_AI_channel_zapping.json`, `nu_view_sport.json`,
`nu_input_game.json` and about a dozen more. Each carries a `provideCondition` describing the
behaviour that triggers it, for example:

```json
"queryInfo": { "duration": 14, "comment": "query channel history from before 14 day" },
"zapping": { "zappingHistoryCount": 8, "zappingHistoryRatio": 20,
"comment": "trigger it after changing the channel in case watching the channel 8 times and 20% ratio" }
```

and a `policyCondition` with `selectRate`, `closeCount`, `timeoutCount` and `suspendCount` —
the prompt suppresses itself if the user keeps dismissing it. One nudge's own text describes the
data basis: "You can receive AI generated recommendations of features, apps, and contents based
on your TV usage history."

The server-side switch `nudge_log_transfer` is `on` (see §7).

### 6.3 Other collectors

- `usr-2/sbin/contentminer` (1 018 220 bytes, mode 0700) — `ContentMinerLogger` with mining,
parsing and action engines, `OnMiningInfoChanged_Full`, `OnMiningInfoChanged_One`, and
`Callback_GetHttpHeaderForSvcReq`, so it is SDP-connected. Preferences directory exists at
`var-18/preferences/com.webos.service.contentminer`.
- `usr-2/sbin/color-info-miner`, `usr-2/sbin/cbox`, `usr-2/sbin/homelaunchpoints`,
`usr-2/sbin/sdp-server-notice`.
- `usr-2/sbin/systemprofile` (mode 0700) — local performance profiling into `/var/webos-profile/`;
no network paths found.

Checked and found not to be telemetry: `tvdataexchanger` (TV-to-TV settings transfer over USB),
`remotelogger` and `snaplog` (local log dumps), `pacrunner` (a proxy auto-config runner, matched
only on the substring "acr").

---

## 7. Server-controlled feature switches

`mnt-6/lg/cmn_data/sdp/sdx/detailconfig.json` is the cached response from
`wiseconfig.lgtvcommon.com` (`service_setting_secure`, path `nextsdp/smartConfig/getConfig`). It
holds 19 configuration blocks, including a `services_info.itemList` of on/off switches that the
server sets. Relevant entries as currently cached:

| Switch | State |
| --- | --- |
| `nudge_service` | on |
| `nudge_server_request` | on |
| `nudge_log_transfer` | on |
| `search_recommendation` | on |
| `voiceid` | on |
| `product_register` | on |
| `thetake_acr` | off |
| `contextual_masa` | off |
| `music_discovery` | off |
| `lgshop_overlay` | off |

`thetake_acr` refers to a second, separate ACR integration (TheTake), disabled for this region.

The same file carries two advertising-identifier allowlists — third-party apps permitted to read
the device IFA:

```
AdIdWhiteList: amazon
NewAdIdWhiteList: amazon, com.disney.disneyplus-prod, com.twin.app.gamingportal,
com.wbd.hbomax, youtube.leanback.v4
```

---

## 8. Consent state as recorded on the device

`mnt-6/lg/cmn_data/sdp/sdx/eula.json`:

```json
{ "deviceCountryCode": "NL", "deviceDateTime": "1752508517",
"eulaChangeReason": "changed", "synchronized": true,
"statusList": [
{ "managementTypeCode": "S_VNG", "versionId": "20231109136_NL", "status": "A" },
{ "managementTypeCode": "S_MKT", "versionId": "20240715263_NL", "status": "A" },
{ "managementTypeCode": "S_SVC", "versionId": "20240716023_NL", "status": "A" },
{ "managementTypeCode": "S_TAG", "versionId": "20250627461_NL", "status": "A" },
{ "managementTypeCode": "S_ADG", "versionId": "20250627462_NL", "status": "A" } ] }
```

All five accepted. `S_SVC` is the service terms and `S_MKT` marketing; `S_ADG` and `S_TAG` are
advertising and, by position and by the `acrGdprAllowed`/`acrAdAllowed` setting names, targeted
advertising. I did not find a file in the image that defines these three-letter codes, so treat
the expansions of `S_TAG` and `S_VNG` as inference.

`mnt-6/lg/cmn_data/sdp/sdx/maketingAllowedDate.json` schedules a re-consent toast via
ActivityManager for `2027-01-07 13:36:03`, two years after the recorded acceptance date of
2025-04-07, described in the file as "Create toast within 2 years that reminds maketingAllowed"
(the misspelling is LG's).

Corresponding Luna settings:

| Key | File | Value |
| --- | --- | --- |
| `livePlus` | `var-18/luna/preferences/option` | `on` |
| `watchedListCollection` | `var-18/luna/preferences/option` | `on` |
| `contentRecommendation` | `var-18/luna/preferences/other` | `on` |
| `aiNudge` | `var-18/luna/preferences/general` | `on` |
| `adCookie` | `var-18/luna/preferences/general` | `on` |
| `screenSaverAd` | `var-18/luna/preferences/general` | `on` |
| `customizedAd` | `var-18/luna/preferences/general` | `off` |
| `doNotSellMyPersonalInformation` | `var-18/luna/preferences/general` | `off` |
| `personalRecommend` | `var-18/luna/preferences/general` | `off`, `changedByUser: false` |

`personalRecommend` being off with `changedByUser: false` means that one is a default, not a
user choice.

---

## 9. Vendors

Searched for the known ACR and audience-measurement SDKs. Results:

- **Alphonso** — present and in use. Sole ACR vendor on this device.
- **TheTake** — referenced as a switch (`thetake_acr`), off; no binary found.
- **Gracenote** — 771 string hits, all in EPG, sports and metadata contexts
(`com.webos.app.sportsteamsettings`). Also the origin of the TMS program and station IDs that
Alphonso returns on a match.
- **Samba TV, Inscape, ACRCloud, Shazam** — no SDK, no endpoints.
- **Nielsen, Comscore, Conviva, Kantar** — no SDK. The handful of substring hits are in spelling
dictionaries, a Python stdlib file, third-party licence texts and one user-guide HTML page.
- **Google Analytics, DoubleClick, Firebase/Crashlytics, Sentry, Branch, Amplitude, Mixpanel,
Segment, Moat, IAS, FreeWheel, SpotX, PubMatic, Criteo, Innovid, Adobe** — no hits.

All outbound analytics on this device goes to LG-operated infrastructure
(`*.lgsdp.com`, `*.lgtvcommon.com`, `*.lgsmartad.com`, `*.lgappstv.com`, `ngfts.lge.com`) or to
Alphonso (`*.alphonso.tv`).

---

## 10. Summary of live status on this device

Enabled and running: ACR (`livePlus: on`, `optin`, Alphonso engine loaded), ad manager with an
active `nl.ad.lgsmartad.com` session, ad overlay service, screensaver video ads, tuner
channel-change reporting to `ibsstat`, the `NL_*` analytics pipeline through rdxd/uploadd, nudge
with log transfer on, and the usage-ranking services.

Enabled but currently unused: the STB detection reporting paths, including the ACR one
(`stbAcrWatchFlag: false`) — the ACR engine is running and matching, but its results are not
being forwarded as set-top-box viewing records.

Disabled: `customizedAd`, `personalRecommend`, `thetake_acr`, and the wider set of `off` switches
in `detailconfig.json`.

The Wi-Fi neighbour scan in §1.5 is the item with no corresponding user-facing control. It is
enabled by a server flag inside the Alphonso SDK, its output sits in the ACR service's state
directory, and it is sent to `/user/location` alongside the fingerprint stream.

---

## Appendix: quick file index

```
ACR
usr-2/sbin/acr2
usr-2/lib/libalphonsosolution.so.1.0.0
usr-2/lib/libas.so.3.0.93
usr-2/lib/libvtcapture.so.1.0.0
usr-2/share/acr/
usr-2/palm/services/com.webos.service.acr/services.json
usr-2/palm/applications/com.webos.app.acr{component,overlay,hdmi1..4}/
etc/palm/activities/com.webos.service.acr/
mnt-6/lg/cmn_data/acr/{data,alphonso,lib}/

Advertising
usr-2/sbin/admanager
usr-2/sbin/adoverlay-service
usr-2/lib/libalphonsoadoverlay.so.1.0.0
usr-2/palm/applications/com.webos.app.{adoverlay,adoverlayex,adhdmi1..4,videoads}/
etc/init/admanager.conf
etc/palm/activities/com.webos.service.ad{manager,overlay}/
mnt-6/lg/cmn_data/{admanager,adoverlay,adlogservice}/

Viewing history
usr-2/palm/applications/com.webos.app.inputcommon/qml/Interfaces/ChannelInfoInterfaces/PersonalDataLogger.qml
usr-2/sbin/pbs
mnt-6/lg/cmn_data/pbs/pbs_config.json

Analytics pipeline
usr-2/sbin/{rdxd,rdx_reporter,uploadd,service-logger}
etc/{rdxd.conf,uploadd.conf}
etc/rdxd.d/
etc/palm/service-logger/rules/
usr-2/share/rdxd/, usr-2/share/uploadd/
mnt-6/lg/cmn_data/uploadd/

Transport and config
usr-2/sbin/sdx
usr-2/palm/sdx/server_addr_version.conf
mnt-6/lg/cmn_data/sdp/sdx/{server_addr_version.conf,detailconfig.json,eula.json,maketingAllowedDate.json}

Profiling
usr-2/sbin/{user-context-manager,user-intent-manager,nudge,contentminer}
mnt-6/lg/cmn_data/nudge/
var-18/preferences/com.webos.service.{usercontextmanager,userintentmanager,contentminer}/

Settings
var-18/luna/preferences/{general,option,other,eula}
etc/palm/defaultSettings.json
```

  • Dalitso
  • Registratie: Augustus 2021
  • Laatst online: 07-09 15:54
# ACR and telemetry components in an LG webOS 3.5 root filesystem

## Scope and method

Subject is an extracted root filesystem from an LG TV, model 43UJ634V of year 2017, webOS 3.5. Service
country NL, firmware 06.10.75 (`mnt/lg/cmn_data/acr/data/firmware_version`).

All binaries are stripped ARM32 ELF. The analysis below is based on `strings` output,
package manifests under `usr/lib/opkg/info/`, configuration files, Luna service role and
activity definitions, and QML/JS application source that ships uncompiled. Where a claim
describes runtime behaviour, it is inferred from symbol names, format strings and Luna
method names rather than observed execution. Claims about state (opt-in flags, cached
files) come from files present in the dump and are direct evidence.

`old_root/` and `var/palm/jail/com.webos.app.browser/` are duplicate views of the same
tree and were excluded from path listings.

---

## 1. ACR: `acr2` and the Alphonso SDK

### Files

| Path | Description |
| --- | --- |
| `usr/sbin/acr2` | ACR daemon, registers Luna name `com.webos.service.acr`. Package `acr2 1.0.0-16.drd4tv.21-r2` |
| `usr/lib/libas.so.3.0.94` | Alphonso ACR SDK, 2.1 MB. Build paths retained: `/mnt/alpha/acr-sdk/sdk-build/git-lg-webos-3.5/acr-sdk/` |
| `usr/lib/libalphonsosolution.so.1.0.0` | LG shim between `acr2` and `libas.so`. Log prefix `LGASAPI` |
| `usr/lib/libsambasolution.so.1.0.0` | Second ACR vendor implementation, Samba TV. Not selected in this configuration |
| `usr/share/acr/acr.a.2.1.4.db.zero.mp3` | Audio reference file used by the SDK, 295 KB |
| `etc/palm/activities/com.webos.service.acr/activity-com.webos.service.acr.start.json` | Boot activity |
| `usr/share/dbus-1/system-services/com.webos.service.acr.service` | D-Bus activation, `Exec=/usr/sbin/acr2` |
| `usr/share/ls2/roles/pub/com.webos.service.acr.json` | Luna role, `inbound: ["*"]`, `outbound: ["*"]` |

`acr2` depends on `libas3.0.94 (>= 3.5.0-12)` per its opkg control file, so the Alphonso
SDK is a hard dependency of the shipped package, not an optional download.

### Startup

The boot activity subscribes to `luna://com.webos.bootManager/getBootStatus` and fires
`luna://com.webos.service.acr/startAcr` with `{"reason":"normal"}` when the signal
`rest-boot-done` becomes true. The service therefore starts on every boot regardless of
user interaction.

### Runtime configuration

`acr2` reads `/tmp/acr.xml`, whose location is pinned by
`mnt/lg/cmn_data/acr/data/config_file_path`. The file is not part of the firmware image;
it is downloaded by `usr/sbin/sdx` (see section 7). The copy captured in this dump:

```xml
<acr_config acr_config_format_ver="1.5" version="3" model_year="2017"
webos_initial_version="webOS3.5" ACR_On="true" capture_method="SOURCE"
max_force_alive="30" no_match_threshold="15" capture_format="YUV420"
ACRServiceLaunched="true" send_data="true" ACRPopup="0" ACRSolution="ALPHONSO"
CountryCode="NL" Activate_UEI="false">
<audio capture="true" sample_rate="48000" channels="2" duration="100"
sleep="0" format="PCM16" pcm_option="dsnoop:0,12" />
<video capture="false" />
<video-capture-max-input-resolution broadcast="2160" external="2160" />
<solution name="ALPHONSO" lib="libalphonsosolution.so.1.0.0" sdk="libas.so"
client_token="LG-webOS35-X-ZKr1ziVgBk7ocB7z">
<dai ota="false" stb="false" />
<overlay support="false" />
<support should-send-first-optout="true" can-create-toast="false" />
<lgchannels capture="false" />
</solution>
</acr_config>
```

The server has ACR enabled for this model and country (`ACR_On="true"`,
`send_data="true"`). Whether it runs is then gated on user consent, covered in section 8.

### What is captured

Audio only, in this configuration. `acr2` contains `DILE_AUDIO_PCM_RegSendPCMCallback`,
`DILE_AUDIO_PCM_StartUpload` and `DILE_AUDIO_PCM_StopUpload`, taking 100 ms windows of
48 kHz stereo PCM16 from ALSA device `dsnoop:0,12`. Fingerprinting happens inside
`libas.so`; raw audio is not sent.

A video path exists and is disabled here. `acr2` carries a `capture::VideoCapture` class,
`CAPTURE_LOCATION_SOURCE` / `CAPTURE_LOCATION_DISPLAY` modes, an `ImageConverter`, and
`CAPTURE_AcquireVtResouce` / `CAPTURE_CreateContext` calls. The config permits 2160p
capture on both broadcast and external inputs.

`capture_method="SOURCE"` means the tap is placed at the input source rather than the
final display composite, so overlays and OSD are excluded from what is fingerprinted.

### Wi-Fi scanning for location

Separate from audio fingerprinting, `acr2` enumerates surrounding wireless networks and
forwards them to Alphonso. The daemon contains a `core::WifiInterface` class that calls
`luna://com.webos.service.wifi/findnetworks` and parses `bssid` and `mac_address` out of
the reply (`[WifiInterface] get network_infos[%s]`). The shim exports this as
`LGASAPI::updateWifiScanInfo/solution:%s/nerwork_info:%s/result:%d` (typo in original).
Inside `libas.so` the corresponding handling is `AS_CLIENT_UPDATE_WIFI_SCAN_INFO`, with
`enable_wifi_scan` as a server-controlled toggle (`Recvd enable_wifi_scan:`,
`Wifi Scanning Start`, `Wifi Scanning Stop`, `Wifi Scanning disabled`), a
`wifiScanJsonOutput:` serialiser, and the fields `wifi_access_points`, `latitude`,
`longitude`.

Nearby BSSIDs resolve to a street-level position through any commercial AP geolocation
database. This is a location channel independent of the `zipcode` value that the SDK
also submits.

### Alphonso backends and API surface

Hostnames in `libas.so.3.0.94`: `prov-lg.alphonso.tv` (provisioning),
`eulacheck.alphonso.tv`.

Request paths:

```
/audio/fingerprint /user /user/location
/user/lookups /user/timed-lookups /user/appsource
/recommendation /recommendation/info /bl/config
/device/config /device/clock /countryList
/latestVersion /log/tar /sdk_debug/stats
```

Query parameters: `alp_uid`, `device_id`, `api_key`, `api_version_major`,
`api_version_minor`, `app_name`, `app_version_code`, `app_version_name`, `country`,
`zipcode`, `ipaddr`, `os_version`, `status`, `current_version`.

Client source files named in the binary indicate the feature set:
`ProvClient`, `UserRegClient`, `EULAClient`, `EULACountryListClient`, `LocationClient`,
`OTTRecmClient`, `OTTRecmFeedbackClient`, `RecmsPollClient`, `RecmUpdateParamsClient`,
`BusinessLogicServerClient`, `ASResultsLookupClient`, `SendBulkLogsClient`,
`ASClockSkewClient`, `MicReaderBufferCB`, `LocationServiceBufferCB`.

`MicReaderBufferCB` and `AudioReader.cpp` are SDK-generic (Alphonso ships the same SDK
for phones). On this platform the audio source is the PCM tap described above, not a
microphone.

### Samba TV as alternative vendor

`libsambasolution.so.1.0.0` is a complete second implementation, selected by setting
`ACRSolution="SAMBATV"` in the config. It carries its own libcurl HTTP client
(`network::HttpClient`, `HttpRequestCurl`), calls `acr_samba_initialize` and
`samba_acr_set_signature`, writes `/tmp/samba.log`, and reads a debug flag from
`/var/luna/preferences/debug_acr_libs`. Its callbacks carry `content_id`,
`ext_content_id`, `ext_source_id`, `title` and `payload`, and it can launch an overlay
application (`event : LAUNCH_ACR_APP (app_id(%s))`) and receive a viewer age
(`event : SET_APPLICATION AGE(%d)`).

The vendor is therefore switchable by server-side configuration without a firmware
update, since the config file is downloaded.

### Presentation applications

Six hidden web applications render whatever a fingerprint match returns, on top of live
video. All are `"visible": false`, `"class": {"hidden": true}`, `"transparent": true`,
and titled `LivePlus`.

| Application | Window group owner |
| --- | --- |
| `com.webos.app.acroverlay` | `com.webos.app.livetv` |
| `com.webos.app.acrcomponent` | `com.webos.app.externalinput.component` |
| `com.webos.app.acrhdmi1` .. `acrhdmi4` | the four HDMI input applications |

Each `index.html` sets an empty input region and `KeyMaskNone`, then loads a remote URL
into an iframe (`present_frm.html`). Teardown calls
`luna://com.webos.service.acr/setVideoPig` to shrink the video window and
`luna://com.webos.service.acr/closedApplication`.

Per-HDMI-port instances mean recognition applies to attached devices, including set-top
boxes, consoles and streaming sticks, not only to the tuner.

### Luna API exposed by `acr2`

`startAcr`, `setACRsetting`, `getACRstatus`, `getACRAppStatus`, `getACRLaunchFlag`,
`getACRSolutionStatus`, `getAudioCaptureStatus`, `getVideoCaptureStatus`,
`getCaptureCondition`, `getCaptureSpeed`, `setCaptureSpeed`, `setVideoPig`,
`setForceAliveTime`, `setSessionControl`, `setCloseCaption`, `closedApplication`,
`sendLChannelInfo`, `sendMessage`, `getCurrentChannelInfo`, `getProductVersion`.

The daemon also subscribes to tuner and power state:
`com.webos.service.tv.broadcast/getCurrentChannel`, `.../getChannelState`,
`com.webos.service.tv.channel/getLastChannelId`,
`com.webos.service.tv.externaldevice/input/getSignalState`,
`com.webos.service.tv.display/getCurrentVideo`, `.../getScreenStatus`,
`com.webos.service.tvpower/power/getPowerState`,
`com.webos.service.tv.dvr/play/isDelayedPlaying`, `.../play/isPauseOnLive`,
`.../record/isTimeshiftBuffering`.

Channel identity, input, DVR and timeshift state accompany each recognition attempt via
`LGASAPI::updateSource/solution/provider/input/channel_name/channel_number/major_number/
minor_number/livetv/vod`.

### State directory

`mnt/lg/cmn_data/acr/` (mirrored at `mnt/lg/user/acr/` and `mnt/lg/flash/data/acr/`):

```
data/config_file_path -> /tmp/acr.xml
data/service_country -> NL
data/sdp_server -> Production
data/firmware_version -> 06.10.75
data/first_optout -> present
lib/ -> empty
alphonso/ -> reference mp3 + log4cplus.properties
```

Paths `acr2` also knows about but which are absent here: `data/optin`,
`data/eula_allowed`, `data/power_off_info`.

---

## 2. Advertising: `admanager`

`usr/sbin/admanager`, package `admanager 2.1.1-101.drd4tv.9-r7`, described in its control
file as "Advertisement Service Manager", source `git://wall.lge.com/service/admanager`.

Hostname compiled in: `info.lgsmartad.com`. Endpoints `/rest/json/v1.0/baseinfo`,
`/rest/json/v1.0/appinfo`, `/rest/json/v1.0/req`, `/rest/xml/v1.0/api/TNC?TNC=`.

Parameters: `app_id`, `down_app_id`, `width`, `height`, `roll_type`, `ifa`, `ifa_type`,
`lmt`, `opt_out`.

It implements the VAST/VPAID tracking vocabulary: `Click Tracking URL`,
`ClickThrough URL`, `ClickThrough ID`, `CompanionClickThrough`, `CompanionClickTracking`,
`ErrorTracker`, plus `=== Tracking Event List ===` and `=== Click Tracking Event List ===`
dump routines.

This component has run on the device. `mnt/lg/cmn_data/admanager/` contains:

- `cache/` with roughly fifty fetched creatives whose filenames encode their source URLs,
from `cdn-aas-campaigns.alphonso.tv/campaigns/images/...` and
`media.bidr.io/alphonso/...`. Several are Dutch-market LG campaigns
(`SmartTV_Netherlands_wedge`, `LG_Wedge_nl_1440x1080`).
- `cookie/ad_cookie`, a libcurl cookie jar for `nl.ad.lgsmartad.com` holding `JSESSIONID`
and the frequency-capping counters `ADSTIME`, `DayCuki0`, `CamDaily0`, `AdSlotDaily0`,
with expiry timestamps in 2026.
- `tmpData/baseInfo.tmp`, the cached slot manifest:

```json
{"advs":{"adServer":"https://nl.ad.lgsmartad.com",
"userAgent":"Mozilla/5.0 (LG smartTV)","sponsoredText":"Sponsored",
"adSlotList":{"adSlotSet":[
{"adSlotName":"Portal/Discovery@Main","adSlot":7689},
{"adSlotName":"Portal/Browser@Main","adSlot":8024},
{"adSlotName":"Portal/Wedge@Main","adSlot":10565},
{"adSlotName":"Portal/LGChannelPause@Main","adSlot":29088}]},
"cmpInfo":{"visibility":false}}}
```

The creative CDN being `alphonso.tv` links the ad delivery path to the same vendor that
supplies the ACR SDK, though the two components are separate processes and the ad slots
here are placements in LG's own UI (home row, browser, pause screen) rather than
ACR-triggered overlays.

Client applications: `com.webos.app.voice/qml/Service/AdManagerService.qml`,
`com.webos.app.searchanddiscovery/qml/Discovery/DiscoveryService.qml`.
Boot job `etc/init/admanager.conf` creates the cache directory at `init-boot-done`.

---

## 3. Channel-change reporting to IBS

`usr/palm/applications/com.webos.app.inputcommon/qml/Service/PersonalDataService.qml`
and `qml/Model/PersonalDataLogModel.qml`.

On channel change, and once three seconds after the channel list loads, the TV posts a
form body to `sdp/livetvwatch.json` on service `ibis_stat_secure`, which resolves to
`https://ibsstat.lgappstv.com/ibs/v2.8/`. Delivery is through
`luna://com.webos.service.sdx/send` with `REQ_SSL_POST_METHOD`.

Body, verbatim from the source:

```
chan_name, chan_code, prev_chan_code, channel_change,
device_src_idx (0 unknown / 1 TV / 2 STB),
dtv_standard_type (1 ATSC / 2 DVB / 3 ISDB),
accept_flag=1, zipcode, timezone, user_id
```

`user_id` is `deviceUniqueId`, obtained together with `watchFlag` from
`luna://com.webos.service.pbsw/getIbsHeaderData`. `usr/sbin/pbs` provides it
(`PBS_UTIL_GetDeviceUniqueId`, `MAIN_MANAGER_GetAuthWatchFlag`) and talks to
`ibs.lgappstv.com` and `ibsstat.lgappstv.com`.

Two gates apply. `watchFlag` must be true, and the server can switch reporting off by
returning `activation_flag != "ON"`. `_getEnableCountry()` restricts the feature to
`KOR`, `GBR`, `ESP`, `FRA`, `BRA`, `RUS`, `DEU`. This unit is NL, so the path is inactive
here. The `accept_flag=1` constant is hardcoded and does not consult `eulaStatus`; the
QML fetches `eulaStatus` but only via `getEula()`, which is not called on the send path.

---

## 4. Crash and analytics upload: `rdxd`

`usr/sbin/rdxd`, package version 3.3.0-172.drd4tv.7-r4, with `usr/sbin/rdx_reporter` and
helper scripts in `usr/share/rdxd/`. `etc/rdxd.conf` sets `AutoUpload=true`.

Three report classes are staged separately: `/tmp/rdxd/crash`, `/tmp/rdxd/analytics`,
`/tmp/rdxd/overview`, spooled through `/var/spool/rdxd/pending` to
`/var/spool/rdxd/uploaded`. Context is gathered by
`make_overview_head.sh`, `make_sdp_crash.sh`, `make_cloud_overview.sh`,
`prepare_cloud_crash.sh`, `filter.sh`, and can include `/var/log/messages` and kernel
logs (`make_kernel.sh`, `make_syslog.sh`, `make_sysinfo.sh`, `make_preboot.sh`).

Two egress paths exist.

**SDP.** `luna://com.palm.uploadd/upload`, with request headers supplied by
`luna://com.webos.service.sdx/getHttpHeaderForServiceRequest`. The endpoint table maps
service `rdx_secure` to `rdx2.lgtvsdp.com/v7.0/`.

**Sumo Logic.** `usr/share/rdxd/conf/cloud.json` holds three hardcoded HTTP collector
URLs on `collectors.sumologic.com/receiver/v1/http/`, with headers
`X-Sumo-Category: OS/webOS/{Crash,Analytics,Overview}` and
`X-Sumo-Name: %nduid%`. The device identifier substituted into the name is
`com.palm.properties.nduid`. Payloads are gzip or deflate encoded. The shipped file sets
`"general": {"enable": false}`; the runtime override location is
`/var/preferences/com.webos.rdxd/cloud.json`, which is not present in this dump.

`rdxd` checks `/var/luna/preferences/devmode_enabled` and suppresses upload when developer
mode is on, and queries `luna://com.webos.settingsservice/getSystemSettings` before
uploading. The `Analytics` category and `ANALYTICS_REPORT_CREATED` marker indicate the
channel carries more than crash dumps.

---

## 5. Remote diagnostics: `remotediag`

`usr/sbin/remotediag` registers `com.webos.service.remotediag` and reads `eulaStatus` and
`eulaInfoNetwork`, keyed on `remoteDiagAllowed`.

Server names: `rone-kic.lge.com`, `rone-eic.lge.com`, `rone-aic.lge.com`,
`rone-tv-kic.lge.com`, `rone-tv-eic.lge.com`, `rone-tv-aic.lge.com`,
`rone-tv-cic.lge.com` (KIC/EIC/AIC/CIC being LG's Korea, Europe, America and China
regional data centres). Also present are literal internal addresses
`165.244.62.249:6120`, `:6230`, `:6240` and `10.185.223.172:80`.

Authentication material: `usr/share/remotediag/device.pem`,
`usr/share/remotediag/server.pem`, with the key unwrapped through
`DILE_CRYPTO_ReadRemoteDiagSecret`.

Once connected it can call `luna://com.webos.audio/setVolume`, `setMuted`,
`luna://com.webos.applicationManager/launch` and
`luna://com.palm.systemservice/setPreferences`, so the channel is control as well as
telemetry. Logs are written to `mnt/lg/cmn_data/remotediag_*.log`.

`usr/sbin/remotelogger` and `usr/sbin/snaplog` are local log collectors with no HTTP
client linked.

---

## 6. Voice: `nlp` and `nlpmanager`

`usr/sbin/nlp` sends recognition traffic to LG's AI backends:
`he-eu-ai.lgthinq.com:443`, `he-us-ai.lgthinq.com:443`, `he-kr-ai.lgthinq.com:443`,
`he-ru-ai.lgthinq.com:443`, with QA variants, plus
`lgs2gb.lpoong.com`, `lgs2us.lpoong.com`, `lgs2kr.lpoong.com`, `lgs2mx.lpoong.com`,
`lgs2au.lpoong.com`. The target is injected per request through an `X-SDP-NLP-URL:` header.

`usr/sbin/nlpmanager` handles the SDP side: `/rest/sdp/v5.0/nlp/service`,
`/rest/sdp/v5.0/nlp/tvtips`, `/rest/sdp/v8.0/search/retrieval`,
`sdp/getNextNsEventList.json`, over service `ibis_secure`. It emits usage logs with
`ibis_valuelist`, `ibis_timezone` and `ibis_device_source_type` parameters. Pinned CA at
`usr/share/ca-certificates/sdp/sdp-ca.pem`.

Gated on `voiceAllowed` / `voice2Allowed`, both false here.

---

## 7. Platform transport: `sdx`

`usr/sbin/sdx` (`com.webos.service.sdx`) is the shared HTTP client for LG cloud services.
Applications do not open sockets themselves; they call `luna://com.webos.service.sdx/send`
with a `serviceName`, a relative `url`, a `methodType` and a body, and `sdx` resolves the
service name against the endpoint table.

`sdx` handles device authentication, EULA synchronisation, terms retrieval and withdrawal,
and it downloads the ACR configuration. Relevant symbols: `sdx::handler::ReqACRHandler`,
`sdx::handler::SDPACRHandle`, `RequestMessage::is_acr_version_check`,
`ACR_VERSION_CHECK`, `ACR_VERSION_DOWNLOAD`, `requestACRVersion`, `getACRPath`,
`_make_dir_acr`, `unmashalling_ACR`, target path `/tmp/acr.xml`, service name
`sdp_check_acr`. Device identity is `LGUDID`, hashed before transmission
(`hashed lgudid is NULL`, `idType is NOT LGUDID`).

The endpoint table is `mnt/lg/cmn_data/sdp/sdx/server_addr_version.conf`, mirrored at
`usr/palm/sdx/server_addr_version.conf`. Entries relevant to data collection:

| Service name | Host | Base path |
| --- | --- | --- |
| `sdp`, `sdp_devauth`, `sdp_terms`, `sdp_check_acr` | `lgtvsdp.com` | `rest/sdp/v8.0/` |
| `ibis`, `ibis_secure` | `ibs.lgappstv.com` | `ibs/v2.8/` |
| `ibis_stat_secure` | `ibsstat.lgappstv.com` | `ibs/v2.8/` |
| `rdx`, `rdx_secure` | `rdx2.lgtvsdp.com` | `/v7.0/` |
| `cdpbeacon_secure` | `cdpbeacon.lgtvcommon.com` | `api/v1/beacon/` |
| `cdp_service_secure` | `cdpsvc.lgtvcommon.com` | `api/v1.0/` |
| `recommend_secure` | `recommend.lgtvcommon.com` | `recommend/v1/` |
| `homeprv_secure` | `homeprv.lgtvcommon.com` | `homeprv/` |
| `nudge_secure` | `nudge.lgtvcommon.com` | `nudge/` |
| `wau_secure` | `wau.lgtvcommon.com` | `wau/v1.0/` |
| `cpv_secure` | `pnv.lgtvcommon.com` | `rest/csi/` |
| `iot`, `iot_push_secure` | `api.lgtviot.com`, `push.lgtviot.com` | `/v1.0/` |
| `voice_proxy_secure` | `netflixvoice.lgtvcommon.com` | `proxy/` |

The `cdpbeacon`, `cdpsvc`, `recommend`, `homeprv`, `nudge` and `wau` names have no
consumer anywhere in this firmware. They appear only in the table itself and in
`PersonalDataService.qml`'s neighbouring service list. On webOS 3.5 they are unused
declarations; they are the beacon and profile endpoints used by later firmware.

Other endpoints outside the SDP table:

- `usr/sbin/pushmanager`: `device.lgeapi.com`, `push.lgeapi.com`,
`push-sender.lgsmartplatform.com`, with `/device/1.0/device`,
`/device/1.0/devices/%s/authkey`, `/push/v1.0/receiver`,
`/push/v1.0/receiver/%s/status`. Staging and QA hostnames are present but commented in
the embedded default config.
- `etc/connman/main.conf`: connectivity probe at `http://lgtvonline.lge.com/` for both
IPv4 and IPv6.
- `mnt/lg/cmn_data/var/palm/data/com.webos.appInstallService/serverInfo`: app store
endpoints.

---

## 8. Consent state on this device

Everything relevant is switched off.

`var/luna/preferences/option`:

```
livePlus = "off"
```

`livePlus` is the settings key backing the "Live Plus" toggle, category `option`, defined
in `usr/palm/applications/com.palm.app.settings/app.js`. Its help text names ACR
explicitly:

> By turning Live Plus on, you are consenting to the collection of television viewing
> information by LG Electronics Inc. ("LGE") through ACR module, which may be shared
> anonymously with third parties to provide you with interactive services. We may also
> share aggregated anonymous information with third parties for marketing purposes.

`var/luna/preferences/general`:

```
adCookie = "off"
customizedAd = "off"
personalRecommend = {"changedByUser": false, "value": "off"}
```

`var/luna/preferences/eula`, `eulaStatus`:

```
acrAllowed false acrOnAllowed false
acrAdAllowed false acrGdprAllowed false
customAdAllowed false customadsAllowed false
cookiesAllowed false thirdPartySharingAllowed false
generalTermsAllowed false additionalDataAllowed false
remoteDiagAllowed false voiceAllowed false
voice2Allowed false chpAllowed false
takeOnAllowed false additional1..5Allowed false
networkAllowed true
```

All ten EULA documents in `eulaInfo.eulaList` show `accepted: false`
(`S_SVC`, `S_PRG`, `S_PRV`, `S_PRD`, `S_PRT`, `S_ADG`, `S_ADC`, `S_ADD`, `S_TAG`,
`S_TAD`).

`mnt/lg/cmn_data/sdp/sdx/eula.json` records one entry, `managementTypeCode: "X_INT"`,
`status: "W"` (withheld), `eulaChangeReason: "initialized"`.

Corroborating file state: `mnt/lg/cmn_data/acr/data/first_optout` exists and
`mnt/lg/cmn_data/acr/data/optin` does not, matching the config attribute
`should-send-first-optout="true"`, which instructs the client to transmit an explicit
opt-out signal once. `mnt/lg/cmn_data/acr/lib/` is empty.

The ad stack is the one component with evidence of past activity, in the form of cached
creatives and unexpired frequency-capping cookies for `nl.ad.lgsmartad.com`. The ad slots
concerned are placements in LG's own interface and are not conditioned on ACR.

Settings UI also disables the `livePlus` and `adCookie` toggles when
`enableHotelMode === "on"` or `supportBNO` is set.

---

## 9. Examined and excluded

`usr/bin/webos-statistics-manager` (`com.webos.statisticsManager`). Despite the name it
writes only to the local DB8 kind `com.webos.statisticsManager.appLaunchHistory:1`, whose
schema is `id`, `launchCount`, `lastLaunchTime`. Its stated purpose in the binary is
"Applaunch event history for preloading apps". No HTTP client is linked. Configuration in
`etc/palm/webos-statistics-manager-conf.json` seeds Netflix with a launch count of 50 to
bias preloading. It flushes on power-off via an activity.

`usr/sbin/prs` (Program Recommendation Service). Scores viewing history locally;
`mnt/lg/cmn_data/prs/prs_config.json` holds weights such as `favorite_program_weight` and
`recommend_history_update_period`. No `curl_easy_perform` reference. The database
`PRS_DB_FIRST_1.db` is zero bytes. It does set `"recmd_origin": "online"`, so it consumes
server-side recommendations even though it does not upload.

`usr/sbin/scd-service`, `usr/sbin/cbox`, `usr/sbin/snaplog`, `usr/sbin/crashd`,
`usr/sbin/faultmanager`, `usr/sbin/remotelogger`, `usr/sbin/rdx_reporter`: none link a
network client.

---

## 10. Summary of network-facing collection paths

| Component | Destination | Data | Active on this unit |
| --- | --- | --- | --- |
| `acr2` + `libas.so` | `prov-lg.alphonso.tv`, `eulacheck.alphonso.tv` | Audio fingerprints, channel and input identity, nearby Wi-Fi BSSIDs, zipcode, IP | No. `livePlus=off`, `acrAllowed=false`, `first_optout` written |
| `admanager` | `info.lgsmartad.com`, `nl.ad.lgsmartad.com` | Ad requests with `ifa` / `lmt` / `opt_out`, impression and click tracking | Has run. Cached creatives and live cookies present |
| `inputcommon` PersonalLog | `ibsstat.lgappstv.com` | Every channel change with previous channel, zipcode, timezone, device ID | No. Country gate excludes NL |
| `rdxd` | `rdx2.lgtvsdp.com`, `collectors.sumologic.com` | Crash dumps, system logs, "analytics" and "overview" reports keyed by nduid | Cloud path `enable: false`; spool empty |
| `remotediag` | `rone-*.lge.com` | Diagnostic session, plus remote control of volume and app launch | No. `remoteDiagAllowed=false` |
| `nlp` / `nlpmanager` | `*.lgthinq.com`, `*.lpoong.com`, `ibs.lgappstv.com` | Voice queries and usage logs | No. `voiceAllowed=false` |
| `pushmanager` | `push.lgeapi.com`, `device.lgeapi.com` | Device registration and push receipt | Registration is unconditional |
| `sdx` | `lgtvsdp.com` | Device auth, EULA sync, ACR config download | Yes. `/tmp/acr.xml` was fetched |

---

## 11. Limits of this analysis

No binary was disassembled. Control flow, and in particular the exact conditions under
which each consent flag is enforced, is inferred from strings and from the QML and JS
sources that ship readable. Two specific gaps:

- Whether `acr2` re-reads `eulaStatus` at runtime, or trusts the `send_data` attribute in
a config file it obtained over the network, is not resolvable from strings alone. The
daemon references both `eulaStatus`, `acrOnAllowed`, `acrAdAllowed` and a
`data/eula_allowed` file it did not create here.
- `/tmp/acr.xml` is server-supplied and mutable. `ACRSolution`, `send_data`,
`video capture` and the Alphonso `enable_wifi_scan` flag can all change without a
firmware update.

Confirming actual behaviour requires either disassembly of `acr2` and `libas.so.3.0.94`,
or network capture from a running device with `livePlus` toggled.
# ACR and telemetry: what changed between webOS 3.5 and webOS 24

A differential reading of two extracted LG root filesystems, seven model years apart.
Companion to `acr-telemetry-report-webos-3.5.md` and `acr-telemetry-report-webos-24.md`, which
hold the full evidence for each side.

## Subjects

| | webOS 3.5 | webOS 24 |
| --- | --- | --- |
| Model | 43UJ634V | 55NANO82T6B.BEUSLJP |
| Model year | 2017 | 2024 |
| Platform | webOS 3.5 | webOS TV 24, platform `10.2.2`, `Rockhopper 10.2.2-5901 (ponytail-paparoa)` |
| Firmware | `06.10.75` | `33.22.86` |
| SoC | — | `K8LPN2`, 1.5 GB DDR |
| Service country | NL | NL |
| SDP region | EIC | EIC |

Same market and same regional data centre on both, so regional configuration differences do not
confound the comparison.

## What this compares

Shipped software: binaries, libraries, service manifests, startup activities, configuration
schemas and application source. Per-unit settings state is out of scope — whether a given
feature was switched on by the owner of either set says nothing about the platform, and the two
units were not in comparable states.

Where a runtime artifact is cited below, it is cited as evidence that a code path exists and
executes, not as a statement about either owner's choices.

Both analyses are static. Neither involved disassembly or traffic capture, so control flow and
enforcement conditions remain inferred from strings, symbol names and the source that ships
uncompiled.

---

## 1. Escalations

### 1.1 Wi-Fi scan results are persisted to disk

Both `acr2` builds enumerate neighbouring access points and pass them to Alphonso. On 3.5 this
is `core::WifiInterface`, calling `luna://com.webos.service.wifi/findnetworks` and parsing
`bssid` and `mac_address` out of the reply. On 24 it is `interface::Wifi` with `OnFindNetworks`,
backed by `ASUtilsReadWifiPropertiesThread` and `UtilsReadWifiProperties.cpp` inside
`libas.so.3.0.93`.

The change is where the result goes. The 24 daemon writes it to a named file:

```
/mnt/lg/cmn_data/acr/data/wifi_network_info
[{"mac_address":"…","signal_strength":"-57"},{"mac_address":"…","signal_strength":"-63"}]
```

`cmn_data` is persistent storage. The scan therefore survives reboot and is readable by any
process with access to that tree, rather than existing only in the daemon's memory for the
duration of a lookup. The 3.5 image has no corresponding path in `acr2`'s string table and no
such file in its state directory.

The scan itself remains server-toggled in both (`Recvd enable_wifi_scan:` in `libas.so`), with no
corresponding control in the TV's settings UI on either platform.

### 1.2 ACR results feed the channel-reporting path

On 3.5, `livetvwatch.json` reporting covers the tuner only. Its body has no field for how the
channel was determined, and `PersonalDataService.qml` restricts the whole feature by country:

```
_getEnableCountry() -> KOR, GBR, ESP, FRA, BRA, RUS, DEU
```

On 24 that function is gone — grepping the equivalent
`com.webos.app.inputcommon/qml/Interfaces/ChannelInfoInterfaces/PersonalDataLogger.qml` for a
country list returns nothing. Gating moved to per-source server flags delivered by `pbs`
(`watchFlag`, `ipWatchFlag`, `stbAcrWatchFlag`, `stbScdWatchFlag`, `stbUeiWatchFlag`), each
independently revocable by the server's reply (`activation_flag`, `ip_activation_flag`,
`stb_acr_activation_flag`).

The body gained a provenance field and a separate STB code path (`sendPersonalLogStb`):

```qml
readonly property int fromWhereAcr: 10
readonly property int fromWhereScd: 11
readonly property int fromWhereUei: 12
```

with `checkSendLogStb` implementing the priority ACR > UEI > SCD. Content recognition identifying
what plays on an attached set-top box, and that result being reported to LG as a viewing record,
has no equivalent in 3.5.

### 1.3 Report timing is randomised

24 delays each channel report by a random interval:

```qml
requestTimer.interval = Math.floor((Math.random() * 10000) + 1) + minTime; // minTime = 10000
```

10 to 20 seconds after the event. 3.5 sent on channel change plus a fixed 3-second call after the
channel list loaded. A fixed offset makes a report trivially correlatable with the user action
that produced it; the jitter removes that property.

### 1.4 Server-facing behavioural profiling appeared

The 3.5 analysis examined two candidates and excluded both. `usr/sbin/prs` (Program
Recommendation Service) scored viewing history locally with no `curl_easy_perform` reference and
a zero-byte database. `usr/bin/webos-statistics-manager` wrote only to the local DB8 kind
`com.webos.statisticsManager.appLaunchHistory:1` with no HTTP client linked.

Neither binary exists in the 24 image. What occupies that role now does have server paths:

| Component | Evidence |
| --- | --- |
| `usr-2/sbin/user-context-manager` | `DBHandler::findHistoryInfoForServer`, distinct from the local `findHistoryInfo`; ranked genre, keyword, intent-type and channel profiles; `displayMonthlyReport` |
| `usr-2/sbin/user-intent-manager` | `QueryProcessor::getRank`, `getHistory`, shared kind with UCM |
| `usr-2/sbin/nudge` | Own kind `com.webos.service.nudge.history:1`; ~15 rule files in `mnt-6/lg/cmn_data/nudge/`; server switch `nudge_log_transfer` |
| `usr-2/sbin/contentminer` | Mode 0700, `ContentMinerLogger`, `Callback_GetHttpHeaderForSvcReq` (SDP-authenticated) |

The nudge rules encode the behaviour they watch for, for example
`"zappingHistoryCount": 8, "zappingHistoryRatio": 20` over a 14-day channel-history window.

### 1.5 Ad surfaces expanded, one of them ACR-driven

3.5 had `admanager` alone, serving placements in LG's own interface (Discovery, Browser, Wedge,
LG Channels pause screen).

24 keeps `admanager` and adds:

- `usr-2/sbin/adoverlay-service` — the same architecture as ACR, with its own Alphonso shim
(`libalphonsoadoverlay.so.1.0.0`), its own copy of the fingerprint database
(`usr-2/share/adoverlay/adoverlay.a.2.1.4.db.zero.mp3`), its own vendor-loader directory
(`/mnt/lg/cmn_data/adoverlay/lib/`), and the check `[ACR] ACR Solution is not Alphonso.`
- `com.webos.app.adhdmi1` through `adhdmi4` — per-HDMI-input overlay containers, mirroring the
`acrhdmi1..4` pattern
- `com.webos.app.videoads` — screensaver video ads against `eic.videoads.lgtvcommon.com`
- `CIFAdService::launchCMPApp` — a consent-management-platform hook

The VAST/VPAID tracking vocabulary (`ClickThrough`, `CompanionClickTracking`, `TrackingEvents`,
impression trackers) is present in `admanager` on both platforms and did not change.

### 1.6 The advertising ID is shared with named third-party apps

`mnt-6/lg/cmn_data/sdp/sdx/detailconfig.json` carries two allowlists of apps permitted to read
the device IFA:

```
AdIdWhiteList: amazon
NewAdIdWhiteList: amazon, com.disney.disneyplus-prod, com.twin.app.gamingportal,
com.wbd.hbomax, youtube.leanback.v4
```

`admanager` on 24 also exposes `getAdid` as a subscribable Luna method, which `acr2` watches in
order to restart itself when the identifier changes (activity named `ccpa changed`). Nothing
equivalent appears in the 3.5 material.

### 1.7 More context accompanies each recognition attempt

3.5's `acr2` subscribed to current channel, channel state, last channel ID, input signal state,
current video, screen status, power state, and DVR/timeshift state.

24's `acr2` retains that set and adds `getCurrentEventList` (EPG programme data),
`getHybridTvState` (HbbTV), `getForegroundAppInfo` and `getForegroundVideoWindow`
(which app is on screen and where the video is placed), `getAllInputStatus`,
`getLatestConnectionInfo` and `getDeviceAuthenticationStatus`.

---

## 2. Reductions

### 2.1 Sumo Logic egress removed

3.5's `rdxd` had a second, non-LG destination. `usr/share/rdxd/conf/cloud.json` held three
hardcoded HTTP collector URLs on `collectors.sumologic.com/receiver/v1/http/`, with headers
`X-Sumo-Category: OS/webOS/{Crash,Analytics,Overview}` and `X-Sumo-Name: %nduid%`.

The 24 image has no `sumologic` string anywhere under `usr-2/` or `etc/`, no `conf/` directory
under `usr-2/share/rdxd/`, and no reference to `com.palm.properties.nduid` in any daemon. Crash
and analytics reports now leave only through `uploadd` to LG's own `rdx_secure` host, per
`etc/uploadd.conf`:

```ini
[server=rdx]
AnalyticsLogURL=log/normal
CrashLogURL=log/crash
```

A third-party log SaaS left the crash and analytics pipeline.

### 2.2 Samba TV dropped as a shipped alternative vendor

3.5 carried `usr/lib/libsambasolution.so.1.0.0`, a complete second ACR implementation with its
own libcurl client, selected by setting `ACRSolution="SAMBATV"` in the downloaded config. 24 ships
Alphonso only; a search for `samba` across the image returns nothing relevant.

This is a narrower reduction than it looks. 24 retains `core::SolutionLoader`, which resolves a
vendor engine at runtime from `/mnt/lg/cmn_data/acr/lib/` (empty in this dump) passing it
`WebOSVersion()` and `FirmwareVersion()`. It also carries a server switch for a different vendor
entirely — `thetake_acr` in `detailconfig.json`, currently `off`, with no corresponding binary in
the image. Vendor substitution moved from a second `.so` visible in the firmware to something
fetched at runtime, which is harder to inspect from an image alone rather than more constrained.

---

## 3. What did not change

### 3.1 The Alphonso SDK is the same generation

| | webOS 3.5 | webOS 24 |
| --- | --- | --- |
| Library | `libas.so.3.0.94` (2.1 MB) | `libas.so.3.0.93` (2.5 MB) |
| Build path | `/mnt/alpha/acr-sdk/sdk-build/git-lg-webos-3.5/acr-sdk/` | `/mnt/alpha/acr-sdk/sdk-build/git-lg-webos-24/acr-sdk/` |
| Hosts | `prov-lg.alphonso.tv`, `eulacheck.alphonso.tv` | identical |

The 2017 set carries the marginally newer SDK build number. The request surface is the same on
both:

```
/audio/fingerprint /user /user/location
/user/lookups /user/timed-lookups /user/appsource
/recommendation /recommendation/info /bl/config
/device/config /device/clock /countryList
/latestVersion /log/tar /sdk_debug/stats
```

with the same parameters, including `alp_uid`, `api_key`, `device_id`, `zipcode`, `ipaddr`,
`app_version_code` and `app_version_name`. Seven model years and two major platform generations
produced no change to the collection interface.

### 3.2 `remotediag` still carries LG-internal addresses

Both images contain `rone-{kic,eic,aic}.lge.com` alongside literal internal endpoints. The 24
binary has everything 3.5 had — `165.244.62.249:6120`, `:6230`, `:6240` and
`10.185.223.172:80` — plus `10.150.25.164:6080`, `10.150.25.244:6080` and `165.244.99.174`.
The service remains capable of control as well as diagnostics.

### 3.3 `cdpbeacon_secure` still has no consumer

The 3.5 report flagged `cdpbeacon`, `cdpsvc`, `recommend`, `homeprv`, `nudge` and `wau` as
endpoint-table entries with no code behind them, expected to become live in later firmware.
Partly borne out: `nudge` and `recommend` now have real consumers, and `wau_secure` was dropped
from the table entirely. But `cdpbeacon.lgtvcommon.com` still appears only in
`server_addr_version.conf` itself, with no caller anywhere in `usr-2/palm` or `usr-2/sbin`, seven
years after it was first declared.

### 3.4 The ACR overlay application pattern

Six hidden `LivePlus`-titled web apps on a dedicated window layer, each loading a
server-supplied URL into an iframe with an empty input region and `KeyMaskNone`, one per HDMI
input plus live TV and external-input variants. Identical on both platforms, down to the
`present_frm.html` contents and the `setVideoPig` / `closedApplication` teardown calls.

---

## 4. Smaller changes

**Device identity.** `nduid` is gone from 24. `sdx` uses `LGUDID`/`UDID` with a
`mnt-6/lg/cmn_data/sdp/sdx/udidflag` marker. For viewing reports, `pbs` derives `user_id`
through `UniqueID::getMacAddress` → `encryptMacAddr` → `convertSHA512`, i.e. a SHA-512 over the
MAC address — stable across a factory reset in a way an `nduid` need not be.

**Consent moved server-side.** 3.5 recorded ten local booleans in `var/luna/preferences/eula`
plus a single `X_INT`/`W` entry in `sdx/eula.json`. 24 keeps a server-synchronised, per-country,
version-stamped `statusList` (`S_VNG`, `S_MKT`, `S_SVC`, `S_TAG`, `S_ADG`) and schedules a
two-year marketing re-consent prompt through ActivityManager
(`mnt-6/lg/cmn_data/sdp/sdx/maketingAllowedDate.json`).

**Capture plumbing.** Audio moved off LG's driver interface layer — 3.5 used
`DILE_AUDIO_PCM_RegSendPCMCallback` / `StartUpload` / `StopUpload` against ALSA device
`dsnoop:0,12` — onto plain ALSA through `capture::AlsaAudioWrapper`. Video capture moved out of
`acr2` (`CAPTURE_AcquireVtResouce`, `CAPTURE_CreateContext`) into the shared library
`libvtcapture.so.1` (`screen-capture-webos` 1.0.0-56), reached through a `VTCaptureWrapper`
class, with a new `DaiFastCapture` path alongside it.

**SDP versioning and hostnames.**

| Service | webOS 3.5 | webOS 24 |
| --- | --- | --- |
| `ibis_secure` | `ibs.lgappstv.com` `ibs/v2.8/` | `ibs.nextlgsdp.com` `ibs/10.1.0/` |
| `ibis_stat_secure` | `ibsstat.lgappstv.com` `ibs/v2.8/` | `ibsstat.nextlgsdp.com` `ibs/10.0.0/` |
| `rdx_secure` | `rdx2.lgtvsdp.com` `/v7.0/` | `rdx2.nextlgsdp.com` `rdx/9.0.0/` |
| `cdpbeacon_secure` | `api/v1/beacon/` | `api/v2/beacon/` |
| `cdp_service_secure` | `api/v1.0/` | `api/v2.0/` |
| `recommend_secure` | `recommend/v1/` | `recommend/nextsdp/10.0.0/` |

The base domain moved from `lgtvsdp.com` / `lgappstv.com` to the region-prefixed
`nextlgsdp.com`. New entries with no 3.5 counterpart: `sdp_logging`, `rdxdev_secure`
(`rdl.lgtvcommon.com`), `nudge_log_secure`, `service_setting_secure`
(`wiseconfig.lgtvcommon.com`), `cpauth_secure`, `wise_resource_secure`, `qcard`, `sdp_nais`.

**Push.** `usr/sbin/pushmanager` (3.5, against `device.lgeapi.com` / `push.lgeapi.com`) is
replaced by `usr-2/sbin/com.webos.service.pushclient`. Not analysed in either report.

**Analytics event catalogue.** 24 emits `NL_*` key-value events through `PmLogCtl logkv`,
collected by `rdxd`; 584 distinct codes appear across the image, with a scheduler
(`usr-2/sbin/service-logger`) running Python collectors from `etc/palm/service-logger/rules/`.
The 3.5 report notes `rdxd`'s `Analytics` class and `ANALYTICS_REPORT_CREATED` marker but does
not enumerate an equivalent catalogue, so this is a difference in what was measured rather than
a confirmed platform change. Worth re-checking the 3.5 image for `NL_` codes before treating it
as one.

---

## 5. Asymmetry in the available evidence

The 3.5 dump contained `/tmp/acr.xml`, the server-supplied ACR policy, readable in full:
`ACR_On`, `send_data`, `capture_method="SOURCE"`, `client_token`, `<video capture="false"/>`,
per-solution `dai` / `overlay` / `lgchannels` flags, and the resolution ceilings.

The 24 dump has no equivalent file. `acr2` still fetches one — the strings `/tmp/acr.xml`,
`/mnt/lg/cmn_data/acr.xml`, `ACR_VERSION_DOWNLOAD`, `requestACRVersion`, `getACRPath` and
`(Sdx) call failed to download acr config : %s` are all present — but the fetched copy lives in
`/tmp` and did not survive extraction.

Consequences for reading the two reports side by side:

- Statements about what the server permits are strong on 3.5 and absent on 24. In particular,
whether video capture is enabled on the newer platform is not established. `acr2` links
`libvtcapture` and carries a `DaiFastCapture` path, but 3.5 also carried complete video capture
code with the config flag set to `false`. Presence of the code proves nothing either way.
- `ACRSolution`, `send_data` and the Alphonso `enable_wifi_scan` flag are all server-set on both
platforms and can change without a firmware update, so neither report's findings on those
points are durable.

Retrieving `/tmp/acr.xml` from a running webOS 24 set would close the largest gap between the two
analyses. Beyond that, the open items are the same on both: no disassembly of `acr2` or
`libas.so`, and no traffic capture to confirm which fields are actually transmitted.

  • Wijnands
  • Registratie: November 2001
  • Laatst online: 16:51
Dit soort dingen lees vraag ik me steeds meer af of er nog schermen zijn die gewoon dom zijn zoals mijn oude philips. Daar zit een chromecast bij die ik alleen in het stopcontact steek als ik 'm nodig heb en een humax met dvb-c

+++Divide By Cucumber Error. Please Reinstall Universe And Reboot +++


  • XiliX
  • Registratie: Januari 2010
  • Laatst online: 22:21
Maar ja, met een Chromecast, doet Google dan niet precies hetzelfde kunstje?

  • mrgnex
  • Registratie: Januari 2014
  • Laatst online: 07-09 20:56
Is er ergens een lijst met welke TV's het betreft en hoe het op te lossen is voor mensen met verschillende mogelijkheden (standaard netwerkspul/aftermarket router/pihole/etc)?

  • antimorian
  • Registratie: Juni 2005
  • Laatst online: 19:11
Toch bijzonder hoe wij dit probleem zelf achteraf op moeten lossen, als er met de gehele privacywetgeving een loopje wordt genomen. Zou dan toch iets van Europa verwachten. Patchen of verbod op verkoop en misschien nog iets met terugwerkende kracht. Of gaat het team met een staal gezicht zeggen dat ze niet wisten dat het niet mocht? Onderhand wel een beetje klaar met deze streken de laatste tijd.

Hoe kan "recall" uberhaupt al in het OS ingebakken worden? Enige waar dit mag lijkt mij de bajes en dat is al discutabel.

Stralen de privacy bescherming weer van afwezigheid. Wel een compleet afluisternet overal in willen bouwen onder terrorisme of noem het excuus maar op. Maar als hier iets tegen het bedrijfsleven voor de consument gedaan moet worden. Wordt een boos mailtje al teveel. Laten we vooral die "maatregelen" en "boetes" niet vergeten.

  • Robkazoe
  • Registratie: December 2002
  • Laatst online: 23:47
Wat weerhoudt iedereen ervan om zijn televisie terug te brengen naar de winkel toe in het kader van een niet deugdelijk product? Product loopt aantoonbaar te bespioneren/je privacy te grabbel te gooien. Dat is niet wat je verwacht van een TV en staat ook niet expliciet aangegeven op de doos/handleiding. Laat de leveranciers maar met een nieuwe komen die dit niet doet.

  • ingmar75
  • Registratie: Maart 2014
  • Laatst online: 23:16
Wijnands schreef op maandag 7 september 2026 @ 16:19:
Dit soort dingen lees vraag ik me steeds meer af of er nog schermen zijn die gewoon dom zijn zoals mijn oude philips.
Menig monitor denk ik. Toen ik een paar maanden terug ging kijken voor een toestel (eindelijk het huis uit) kon ik vrijwel geen TV vinden zonder dat het een Smart-TV was, een paar peperdure schermen voor bedrijven terzijde.

En het is een LG. Ik heb deze nooit verbinding gegeven omdat ik gewoon een groot scherm wilde, geen apps. Of die nu aan het neuzen is bij de appartementen rondom die van mij voor open netwerken, weet ik niet.

Had achteraf net zo goed voor een tweedehands plasma-TV kunnen kijken. :P

[ Voor 5% gewijzigd door ingmar75 op 08-09-2026 12:30 ]


  • Wim1147
  • Registratie: April 2023
  • Laatst online: 13:20
Wijnands schreef op maandag 7 september 2026 @ 16:19:
Dit soort dingen lees vraag ik me steeds meer af of er nog schermen zijn die gewoon dom zijn zoals mijn oude philips.
Als je zoekt op de Tweakers Pricewatch, dan zijn er nog een aantal te vinden. Op dit moment staan er nog (slechts) 25 niet 'smart' toestellen in vermeld. Andere oplossingen zijn beamers of de kringloopwinkel.
ingmar75 schreef op dinsdag 8 september 2026 @ 12:28:
[...]Menig monitor denk ik.... En het is een LG.
Onlangs had Gamers Nexus een item over LG monitoren die hun gebruikers bespioneerden en via Windows Update 'LG Adware' installeerden. Dit is ook door Tweakers opgepakt. Het artikel op Tweakers is hier te vinden en het item van Gamers Nexus hier.

  • ingmar75
  • Registratie: Maart 2014
  • Laatst online: 23:16
Wim1147 schreef op dinsdag 8 september 2026 @ 13:20:
Onlangs had Gamers Nexus een item over LG monitoren
Klopt, ik bedoelde dan ook dat de tv die ik gehaald had een LG is, monitor heb ik al een stuk langer, een Acer die het misschien heel langzaam aan het begeven is.

Vind het wel een dubbel standaard, dat bedrijven zulke dingen doen terwijl menig consument regelmatig niet vertrouwd wordt. Maar ik denk dat dat een beetje off-topic is.

[ Voor 5% gewijzigd door ingmar75 op 08-09-2026 13:41 ]


  • Wijnands
  • Registratie: November 2001
  • Laatst online: 16:51
ingmar75 schreef op dinsdag 8 september 2026 @ 12:28:
[...]

Menig monitor denk ik. Toen ik een paar maanden terug ging kijken voor een toestel (eindelijk het huis uit) kon ik vrijwel geen TV vinden zonder dat het een Smart-TV was, een paar peperdure schermen voor bedrijven terzijde.
Nou ben ik zelf niet van de hele grote schermen dus ik zat voor de aardigheid s in de klasse 40-48 inch te neuzen. Kwam maar een handjevol schermen met goede responsetijd en geen smart componenten tegen

+++Divide By Cucumber Error. Please Reinstall Universe And Reboot +++


  • relativity
  • Registratie: Februari 2012
  • Laatst online: 20:30
Ik was zelf aan het zoeken op mijn LG tv of ik gegevens kon terug vinden... Maar zelfs als root user kan ik geen logs of wav files vinden.

Iemand een idee? Daarnaast heb ik alles op dns level geblokkeerd. Alle dns requests worden al geredirect door mijn firewall op een interne revolver.
Pagina: 1