Is Your New TCL HDTV (Made In China) A Security Risk?
There’s been a huge amount of concern this year about the security implications of technology that originates in China or is owned by Chinese companies. That was, after all, at the heart of the fight by the Trump Administration to ban the popular social networking app TikTok, or at least to force a sale of it. The U.S. government has also cracked down on the manufacturers Huawei and ZTE, and the omnibus/coronavirus rescue package recently passed by Congress even included $1.9 billion to help companies remove equipment from those two companies.
Recently, a pair of security researchers raised the alarm about another Chinese tech company, the TV manufacturer TCL, which makes some of the most popular televisions available in the U.S.
The website of the researcher and hacker known as Sick Codes, in a blog post in November, pointed out “extraordinary vulnerabilities” in TCL’s Android TVs.
“Near the end of September, while conducting research into low-end Android boxes, I came across a number of serious flaws in the way in which these devices were being designed,” the post said. “Without delving into the nuances of each device, all of the Smart TV products are Android-based.”
The researcher discovered that they could easily access the entire file system of the devices.
“Why would an Android device need a web server running on a non-standard port?” he asked. “What kind of manufacturer publishes the whole file system of a device?”
Sick Codes was later joined in his work by another researcher named John Jackson, and in October the two of them both notified TCL which, after a delay in response, said they would patch the issue.
In an interview with Tom’s Guide, Sick Codes sent a URL that provided “full access to the file system of a TCL smart TV in Zambia,” and the writer was able to browse the directories of that person’s TV.
And in another interview with Security Ledger, Sick Codes said that “anybody on an adjacent network can browse the TV’s file system and download any file they want.”
TCL Android TV
TCL issued a statement to the media, as reported by Tom’s Guide:
“TCL was recently notified by an independent security researcher of two vulnerabilities in Android TV models,” the statement said. “Once TCL received notification, the company quickly took steps to investigate, thoroughly test, develop patches, and implement a plan to send updates to resolve the matter. Updating devices and applications to enhance security is a regular occurrence in the technology industry, and these updates should be distributed to all affected Android TV models in the coming days.”
“Going forward, we are putting processes in place to better react to discoveries by 3rd parties [and] performing additional training for our customer service agents on escalation procedures on these issues as well as establishing a direct reporting system online,” TCL said further, in a statement to PC Mag.
It’s worth pointing out, as stated by Sick Codes in the comments to the original post, that the issue they pinpointed only applies to TCL’s Android TVs, and not to its Roku TVs, which are the majority of what TCL sells in North America. In fact, TCL only brought Android TVs to the North American market for the first time in July.
On Tuesday, the Department of Homeland Security released a new report called “Data Security Business Advisory: Risks and Considerations for Businesses Using Data Services and Equipment from Firms Linked to the People’s Republic of China.”
TCL is not mentioned in the report, nor are televisions.
“The PRC’s data collection actions result in numerous risks to U.S. businesses and customers, including: the theft of trade secrets, of intellectual property, and of other confidential business information; violations of U.S. export control laws; violations of U.S. privacy laws; breaches of contractual provisions and terms of service; security and privacy risks to customers and employees; risk of PRC surveillance and tracking of regime critics; and reputational harm to U.S. businesses,” the report said.
(TLB) published this article from 19FortyFive.com
Header featured image credit: TCL 4K HDTV
, a technology writer for The National Interest, is a journalist, essayist and film critic, who is also a contributor to Philly Voice, Philadelphia Weekly, the Jewish Telegraphic Agency, Living Life Fearless, Backstage magazine, Broad Street Review and Splice Today. The co-founder of the Philadelphia Film Critics Circle, Stephen lives in suburban Philadelphia with his wife and two sons. Follow him on Twitter at @StephenSilver.
Stay tuned to …
The Liberty Beacon Project is now expanding at a near exponential rate, and for this we are grateful and excited! But we must also be practical. For 7 years we have not asked for any donations, and have built this project with our own funds as we grew. We are now experiencing ever increasing growing pains due to the large number of websites and projects we represent. So we have just installed donation buttons on our websites and ask that you consider this when you visit them. Nothing is too small. We thank you for all your support and your considerations … (TLB)
Comment Policy: As a privately owned web site, we reserve the right to remove comments that contain spam, advertising, vulgarity, threats of violence, racism, or personal/abusive attacks on other users. This also applies to trolling, the use of more than one alias, or just intentional mischief. Enforcement of this policy is at the discretion of this websites administrators. Repeat offenders may be blocked or permanently banned without prior warning.
Disclaimer: TLB websites contain copyrighted material the use of which has not always been specifically authorized by the copyright owner. We are making such material available to our readers under the provisions of “fair use” in an effort to advance a better understanding of political, health, economic and social issues. The material on this site is distributed without profit to those who have expressed a prior interest in receiving it for research and educational purposes. If you wish to use copyrighted material for purposes other than “fair use” you must request permission from the copyright owner.
Disclaimer: The information and opinions shared are for informational purposes only including, but not limited to, text, graphics, images and other material are not intended as medical advice or instruction. Nothing mentioned is intended to be a substitute for professional medical advice, diagnosis or treatment.