hn.today

Deshittification Part 2: Bypassing the App Store Gatekeeper

fabricati-diem.inform.social13 points2 comments
Screenshot of Deshittification Part 2: Bypassing the App Store Gatekeeper

A hands-on investigation of an LG OLED running WebOS instrumented behind an OpenBSD gateway and Unbound DNS shows the OS actively enforces an artificial telemetry toll before allowing access to its Content Store. When telemetry and ad domains (notably wiselg.com) were blocked at DNS, the store returned error E5.48.XV while other network features and preinstalled apps continued to work. Resolver logs captured repeated NXDomain responses for wiselg.com rather than any attempt to contact app repositories, proving WebOS performs a mandatory pre-flight tracking check. Temporarily allowing those domains let the store open, reinstall Netflix, and stream 4K immediately; reapplying the block reinstated the lockout even though the streaming binary itself had no technical dependence on the telemetry servers.

That gatekeeping behavior is presented as a violation of GDPR Article 7(4) because it conditions a basic service (app installation/use) on consenting to optional data collection. A further line of defense - described as a cold-boot consent trap - appears to trigger network sabotage on hard reboot by injecting TCP RST floods against third‑party app connections. A sanitized raw analysis log and time‑synced photos map UI errors to DNS and TCP events, and a formal GDPR complaint has been filed with LG’s DPO. Readers are urged to collect packet captures, timestamped screenshots, and publish logs to build enforceable evidence for regulators.

Read on fabricati-diem.inform.social2 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.