The Register® — Biting the hand that feeds IT

Feeds

Samsung: Smart TV security hole is so minor we'll fix it immediately

Tellies leak private info to hackers, nothing to see here

Samsung has downplayed the significance of a data-leaking security bug in its Smart TVs, but promised to close the hole by January.

Earlier this month Malta-based startup ReVuln said it had discovered a vulnerability that allows hackers to remotely copy data off USB drives connected to a Samsung TV LED 3D and other Smart TVs, among other exploits.

ReVuln published a video clip to back up its assertions, and warned the security flaw grants hackers access to personal information and allows to them to plant malware or even change channels on vulnerable sets. Lisa Vaas of Sophos has listed all the possibilities here.

Luigi Auriemma of ReVuln told El Reg that the vulnerability "affects almost all the Samsung televisions of the latest generations", meaning that multiple models are affected.

ReVuln sold information about the flaw to its customers rather than report it to Samsung, which is consistent with its general policy of non-disclosure. Although ReVuln did not go into details about the hole, Samsung said in a statement that it has isolated the problem:

We have discovered that only in extremely unusual circumstances a connectivity issue arises between Samsung Smart TVs released in 2011 and other connected devices. We assure our customers that our Smart TV’s (sic) are safe to use.

We will release a previously scheduled software patch in January 2013 to further strengthen Smart TV security. We recommend our customers to use encrypted wireless access points, when using connected devices.

Adam Gowdiak, a Polish researcher who uncovered a possible mechanism for infecting set-top boxes with malware earlier this year, said the vulnerability discovered by ReVuln bears the hallmarks of a Universal Plug and Play (UPnP) bug.

"We haven't looked into Samsung SmartTVs, the YouTube video gives little information, but it looks like UPnP or DLNA [Digital Living Network Alliance] issue to us," said Gowdiak, whose Security Explorations firm is one of the few consultancies probing the emerging world of TV security in any depth.

A Samsung Smart TV can be used to browse the internet, post updates to social networks, purchase movies and perform many other tasks. These next-generation tellies are commonly, but wrongly, thought to be immune from malware and hacking attacks. In reality smart TVs and set-top boxes are becoming more like PCs than the dumb devices of yesteryear, a factor that makes information security a potential concern.

And, let's face it, if it's electronic, someone will find a way to compromise it. ®

Re: Can it, for example, turn on a camera

If you're wanking to Babestation you've got bigger problems than a security hole in your Smart TV

9
0

Pah, Toothbrushes, Doorbells, thats nothing.

Someone hacked my toaster to make it talk, and now it never shuts up asking if I want toast.

6
0

No!

Not...change the channel! Have these fiends no depths to which they will not sink?

3
0

Shame these Smart TVs' updates tend to not be issued by the manufacturers that long. One or two updates are the norm, if you're lucky, and if there's a security vulnerability after that - tough. You don't even get an Android-style enthusiast community to provide ongoing software updates because all the software is proprietary rubbish.

This problem will only get worse.

1
0

Re: Can it, for example, turn on a camera

Is the AC in fact Tom Brooker, as mentioned in this incisive article on Samsung smart TV's ?

http://www.thedailymash.co.uk/news/society/smart-tv-disgusted-by-owner-2012121954108

1
0

More from The Register

 breaking news
Apple cored: Samsung sells 10 million Galaxy S4 in a month
Beware of South Koreans bearing Android
Microsoft reveals Xbox One, the console that can read your heartbeat
Upgrades Live service – and no always-on requirement
US boffin builds 32-way Raspberry Pi cluster
Beowulf cluster built for the price of a single PC
Review: HP Pavilion 14 Chromebook
All roads lead to Chrome?
Euro PC shipments plummet into bottomless pit of DOOOOM
11th quarter of decline, 20pc drop on last year - Gartner
STROKE this mouse to make apps POP, says Microsoft
Windows 8 Start button comes to Redmond's rodents
Nintendo throws flaming legal barrel at YouTubing fans
All your walk-through vid revenue are belong to us

Hands on with Hyper-V 3.0 and virtual machine movement

Our award-winning Regcasts have teamed up with training provider QA for the deepest of deep dives into Hyper-V, including a live demo.

Understand VM movement - just click to play, or go here for a bigger version.