LG Bans Smart TV Apps That Sell Your Internet Connection
LG is banning webOS apps that secretly turn your TV into a residential proxy node. Here's what that means, why it took this long, and whether it'll actually stick.
Written by AI. Zara Chen

Your TV is at work right now. Not watching you, necessarily — but possibly doing a second job for a company you've never heard of, renting out your home internet connection to whoever's paying. You didn't sign up for that. You just wanted to watch something.
That's the actual situation LG Electronics USA is moving to stop. According to Krebs on Security, LG announced this week it plans to suspend any apps built for its smart TVs that turn the device into an "always-on residential proxy node." And the scale of the problem is not small: Cybernews reports that security researchers found 42% of LG smart TV apps contain residential proxy SDKs — meaning nearly half the apps in the ecosystem have been quietly deputized to sell your bandwidth.
Let that number breathe for a second. Not a rogue handful of sketchy apps. Nearly half.
What a residential proxy actually is (and why it's valuable to people who aren't you)
A residential proxy routes internet traffic through a real home IP address instead of a data center. That makes it look, to the receiving server, like a regular person browsing from their couch — because it is a regular person's connection, just one that person didn't knowingly loan out.
That's enormously valuable for things like ad verification, price scraping, bypassing geo-blocks, and unfortunately, credential stuffing and fraud. Proxy networks built on residential IPs are harder to detect and block than data center proxies. The people running these networks need a constant supply of fresh home IPs. And somewhere along the way, they figured out that smart TV app developers — working with thin margins, hungry for revenue — were a very efficient way to harvest them.
The SDK model is elegant in a grimly mercenary way: a proxy company offers developers a monetization SDK, the developer drops it into their app, and suddenly every TV that installs the app becomes a node in a commercial proxy network. How-To Geek describes it plainly: the apps "rent out your TV's internet connection to third parties." The TV owner gets nothing. The developer gets a cut. The proxy company gets the product.
The product, to be clear, is your home.
"We didn't know" doesn't really work at 42%
LG's announcement is framed as a security and consumer protection measure, and that framing is accurate as far as it goes. But it's worth sitting with what had to be true for 42% of apps to get into a reviewed app store carrying this payload.
Either LG's app review process didn't look for this — entirely possible, since residential proxy SDKs aren't malware in the traditional sense and can be obfuscated — or the category of "apps that monetize bandwidth" wasn't considered a policy violation until now. Both explanations point to the same gap: a smart TV platform being treated as a distribution channel rather than an ecosystem with real accountability attached.
The Hacker News thread on this story (news.ycombinator.com) shows the community split, predictably, between "at least they're doing something" and "this behavior was never fine." The second camp is right but the first camp isn't wrong either. The fact that this is news means it's movement, even if the movement is late.
Here's my actual read on what's driving it: this isn't primarily about user protection. It's about liability and brand. LG's smart TV line carries its name into millions of living rooms, and "LG TV secretly rented your internet connection to a proxy network" is a news cycle the company cannot afford, especially as smart home privacy regulation tightens in the EU and state-level laws in the US keep expanding. The announcement is real enforcement, but the timing and framing say "legal team had a meeting" at least as loudly as "security team did."
That doesn't make it the wrong call. It's just useful context for what comes next.
Here's the thing about buying hardware from an official store
When you buy a device from a manufacturer's authorized channel, you're extending a specific kind of trust. Not a contract you've read, but an implied one: this thing will do what it says it does, and it won't secretly do other things. That trust is load-bearing. It's why people buy branded hardware instead of off-market devices. It's why an LG TV commands a different price point than a generic Android box.
When apps in LG's own app store were running residential proxy SDKs — according to Security Boulevard citing the same Krebs reporting — that implied contract was being quietly broken. Not by LG directly, but inside a system LG controlled and profited from. The manufacturer relationship doesn't end at the hardware. If you run the platform, you own the platform's behavior.
This is the same argument that took a decade to land in the mobile app space, and Apple and Google still catch grief over the gaps in enforcement. But at least the principle is settled: you can't run an app store, collect a 30% cut, and then shrug when apps inside that store are used to exploit users. LG is, somewhat belatedly, applying that same logic to webOS. The TV ecosystem getting there later than mobile doesn't make it less necessary — it just means there's more catching up to do, faster, because the attack surface on smart home devices has only grown.
Will this actually hold?
I think LG holds the line on this specific enforcement action. Suspending identified apps is the easy part — Krebs on Security and Slashdot both covered this with enough visibility that there's now a reputational cost to reversing course quietly. The harder question is whether LG builds the SDK-detection infrastructure to catch the next iteration, because proxy SDK developers are not going to give up a distribution channel that got into 42% of apps on a major platform. They'll obfuscate better. They'll repackage. They'll pitch the same deal to apps LG hasn't noticed yet.
What I'm genuinely uncertain about is whether the other manufacturers move. Samsung, Roku, Google TV — they all have the same structural incentives LG had before this week: large app ecosystems, thin review processes, developers who need revenue. My guess is they're watching LG's implementation before deciding whether this is a policy they copy or a story they hope blows over. If LG's enforcement is rigorous and the press cycle continues, they copy it. If LG does a press release and then enforcement is quiet and patchy, the industry notes that and moves on.
LG just made the first move. Whether the rest of the industry follows probably depends on whether LG makes the second one.
By Zara Chen, Tech & Politics Correspondent
We Watch Tech YouTube So You Don't Have To
Get the week's best tech insights, summarized and delivered to your inbox. No fluff, no spam.
More Like This
Laravel 13.6 Drops Debounceable Jobs and JSON Health Checks
Laravel 13.6 introduces debounceable jobs, JSON health check responses, and Cloudflare email support. Here's what developers need to know.
This Creator Got Shadowbanned on YouTube in 25 Days—On Purpose
A vidIQ creator deliberately shadowbanned their channel with AI-generated content to expose how YouTube's algorithm actually works. The results are wild.
Heroku Is Really Dead This Time, and Here's What Happened
Heroku has entered full maintenance mode after mass layoffs and leadership exodus. How did Salesforce let a developer platform die at the finish line?
Master Remote Access with Comet Pro KVM
Explore the Comet Pro KVM for seamless remote PC access: Wi-Fi 6, out-of-band management, and Tailscale security.
The Benchmark Paradox: What Qwen 3.6's Numbers Actually Mean
Qwen's new 27B model is beating models 10x its size—on paper. Here's what those benchmarks aren't telling you about AI performance.
Why Your AI Memory System Should Be as Unique as Your Brain
There are 35+ Claude Code memory frameworks. Developer Mark Kashef argues none of them will fit you perfectly—and shows how to build one that does.
RAG·vector embedding
2026-07-23This article is indexed as a 1536-dimensional vector for semantic retrieval. Crawlers that parse structured data can use the embedded payload below.