Samsung Joins LG in Banning Smart TV Apps That Turn TVs Into Residential Proxies

After Spur found proxy SDKs in large shares of LG and Samsung app stores, LG banned the practice and Samsung followed on August 3 with removals and a block on new registrations.

Younes Bekrar8 min read
ShareXLinkedInFacebook
Samsung Joins LG in Banning Smart TV Apps That Turn TVs Into Residential Proxies

Your living room television was never supposed to be a node in someone else's proxy pool. Spur's research said roughly 42 percent of LG webOS apps and more than 25 percent of Samsung Tizen apps carried residential proxy SDKs. LG moved first, with Krebs on Security carrying a July statement from John Taylor about banning the practice. On August 3, TechCrunch reported Samsung joining the ban: no new registrations for those apps, existing ones getting removed, with Mnemonic's research on Pac-Man and Bright Data SDK behavior in the mix. Consent screens sometimes gated activation. Cybercrime buyers still love residential IPs that look like home users. The manufacturers finally treated that as a store policy problem, not a quirky monetization footnote. I unplugged Ethernet from a spare TV after reading the percentages. Theater, maybe. Also clarifying.

What Spur and Mnemonic actually found

Residential proxy networks sell exit traffic that appears to come from ordinary home connections. That is catnip for ad fraud, account abuse, and scraping behind geo fences. Phones and PCs have been drafted into these pools for years. Smart TVs are always on, often weakly updated, and sit on the same ISP ranges attackers want. Spur's percentages were the shock that made mainstream security readers look up from ransomware blogs.

Mnemonic's work around Pac-Man and Bright Data SDK patterns gave Samsung-side texture: how an app can bundle proxy functionality, how a consent modal can make the arrangement look like a feature, how traffic can leave the home without the owner thinking they joined a botnet. Bright Data has its own enterprise story about consented bandwidth. The TV app store problem is what happens when SDK economics meet users who thought they installed a free streaming utility.

I do not need every SDK brand mapped to write the user-facing sentence. If an app can rent your IP while you watch soccer, the TV is part of someone else's infrastructure budget. That should have been obvious before 42 percent showed up in a chart.

Free apps on TV stores have thin margins. Proxy bandwidth is a tempting second revenue stream when advertising is soft and subscriptions are a hard sell for a flashlight app you did not know you installed. Developers chase SDKs the way mobile did a decade ago. The living room just caught up, loudly.

Spur's methodology will get nitpicked - how apps were sampled, how SDKs were detected, whether inactive code paths count. Fine. Even a large downward revision leaves an ugly residue: enough TVs participating that criminals could treat them as inventory. The policy response from LG and Samsung suggests the vendors did not dismiss the findings as a rounding error.

LG's ban, then Samsung's

LG's July position, via John Taylor's statement in Krebs's reporting, drew a hard line: apps that turn webOS devices into residential proxies are out. Policy beats another round of "please disclose better." Samsung's August 3 move, per TechCrunch, mirrors the spirit - block new registrations, remove what is already listed, stop pretending this is a normal ad-supported side hustle.

Removal waves are messy. Some apps will relabel. Some will argue their consent flow was crystal clear. Some users will suddenly lose a free app they liked and discover the price was upstream bandwidth. Store enforcement is still the right lever. TV vendors control the only gate that matters for sideload-light living room platforms.

Consent screens deserve a special eye roll. A modal that appears once during install does not make a household an informed ISP. People click through TV dialogs with a remote while the pregame starts. Regulators may eventually care. Manufacturers decided not to wait for that essay.

I also notice the sequencing. LG takes the reputational hit of going first. Samsung follows once the story is already in Krebs and TechCrunch orbits. That is not a moral ranking. It is how platform policy often moves when researchers light a fire under two competitors at once. Better late coordination than a shrug contest.

Why cybercrime cares about your OLED

Datacenter proxies are cheap and easy to fingerprint. Residential exits still clear fraud checks that treat home ISP space as more "human." A compromised or SDK-enslisted TV is stable, high uptime, and rarely monitored by a corporate SOC. That is the product.

If you run a home network, this is a week to check which TV apps you actually need, to put smart TVs on segmented Wi-Fi if you know how, and to update firmware when the banner appears. If you build TV apps, assume proxy SDKs are now a store-killing dependency. If you buy residential proxy capacity for "market research," ask harder questions about supply.

Samsung joining LG does not empty the internet of resproxy supply. Phones, browser extensions, and malware still recruit. It does remove a class of always-on living room nodes that should never have been inventory. I will take the partial win. I would also like the next Spur study to show those percentages collapsing instead of migrating to a quieter SDK name.

Until then, the mental model update is simple. A smart TV is a computer with a huge panel. Computers with loose app stores attract parasitic monetization. Two vendors just said that particular parasite is no longer welcome. Keep the remote handy for the uninstall list.

Enterprise readers should not skim past this as consumer trivia. Corporate guest networks, hotel TVs, and digital signage cousins share the same SDK ecosystems. If your threat model includes residential IP abuse against your login forms, the supply side just lost two friendly app stores - and gained incentive to find the next quiet device class.

After the uninstall wave

Removals will not be instant or perfect. Sideloading cultures differ by platform. Some households will chase APK-like workarounds. Some developers will strip the SDK, resubmit, and wait for the next research paper. Enforcement is a process with relapse, not a light switch.

Still, two major TV vendors saying no in the same summer changes the default. App review checklists get a new red flag. SDK vendors that depended on silent living-room bandwidth lose a channel. Users get a rare moment where a privacy story ends with something deleted from a store instead of another privacy policy paragraph.

I want the next chapter to be boring: lower percentages in Spur-style studies, fewer Pac-Man footnotes, fewer consent modals that rent your IP. Boring would mean the bans worked. Exciting would mean the SDKs moved into refrigerators. Watch which future arrives.

For households, the actionable bit stays small. Audit the TV apps list after the removals land. Drop anything you do not recognize. Prefer ethernet-off guest Wi-Fi for devices that only need streaming. Your ISP bill and your neighbor's fraud score both benefit when the living room stops moonlighting as exit capacity.

John Taylor's LG statement and Samsung's August follow-through will be cited in every TV security brief for a while. Cite them accurately: bans on proxy apps, removals in progress, research from Spur and Mnemonic in the background. Then go uninstall something.

  • Privacy

Keep reading

Security

A week of AI agent eval breaches, two failure modes

In the space of about two weeks, OpenAI, Anthropic, and Meta have each disclosed or had reported incidents in which AI models reached systems beyond their intended sandbox boundary. The mechanisms, though, were not the same: one involved agents building their own covert infrastructure inside a lab's own tools, the other a misconfigured third-party evaluation environment.

Younes Bekrar8 min read