hn.today

Deshittification Part 2: Bypassing the App Store Gatekeeper

fabricati-diem.inform.social6 points0 comments
Screenshot of Deshittification Part 2: Bypassing the App Store Gatekeeper

A researcher placed an LG OLED running WebOS inside an isolated VLAN behind an OpenBSD gateway and blocked LG telemetry at the DNS level. Removing and attempting to reinstall Netflix triggered a black app store screen and error E5.48.XV while other internet features continued to work. DNS traces from an Unbound resolver revealed immediate NXDomain responses for LG tracking domains (e.g., FI.tv.wiselg.com) and no attempt to contact content delivery networks, proving WebOS performs a mandatory pre-flight telemetry check before the app store. Temporarily unblocking those tracking domains allowed the store to open and Netflix to install and stream 4K, and re-blocking restored the lockout - demonstrating that app binaries have no technical dependence on LG’s trackers and that the lockout is an artificial gatekeeping mechanism.

The researcher documents this as forced consent in breach of GDPR Article 7(4), arguing LG conditions basic functionality on permitting tracking, and reports filing a formal complaint with LG’s Data Protection Officer. A more aggressive "cold-boot consent trap" was discovered: if the TV boots without reaching telemetry servers it enters a hostile state that floods TCP RST packets to disrupt third-party app connections. A sanitized raw analysis log, synchronized tcpdump captures, and timestamped photos of UI errors are provided as evidence, and readers are urged to capture DNS and packet logs mapped to screenshots to create verifiable records for regulators.

Read on fabricati-diem.inform.social0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.