logoalt Hacker News

rickdeckardtoday at 6:10 AM3 repliesview on HN

> Yup. I'm sitting on one that doesn't even require an internet connection, only RF down the TV antenna input. I'm waiting for my model to go EOL before I release it.

So no responsible disclosure, I see.

Not knowing any more details, it still sounds like you'd still need the user to tune to the actual frequency on the correct receiver (to cause some buffer overflow?). But then still there's no internet to do anything. So you'd need some very specific f/up exploit to then change local settings on the device I imagine.

Either way, would be a great opportunity to demonstrate this in a video, now that there's attention on the topic, to further amplify the pressure on LG's "terrible security posture" as you say.


Replies

michaelttoday at 7:45 AM

> So no responsible disclosure, I see.

If I, a corporation, declare that I only accept security reports carved on clay tablets in ancient greek and hand-delivered to my office in Timbuktu during a total solar eclipse - does that stop responsible security researchers from disclosing their findings publicly?

Of course not.

If the guy sends a clear message to the best public contact address he can find with 15 minutes of searching; and gives them 30 days to patch before publicly disclosing the bug; then he's performed responsible disclosure.

The vendor's corporate policies and release cycles and contact addresses and triage procedures are their problem.

RobotToastertoday at 8:46 AM

> So no responsible disclosure, I see.

If the manufacturers responsibly included a responsible way to install custom software/firmware, perhaps people would feel more inclined to help them. Their current attitude buys them very little goodwill.

Retr0idtoday at 6:17 AM

> So no responsible disclosure, I see.

Huh?

show 2 replies