Samsung today said it has restricted new app registrations that contain residential proxy functionality and is working to remove existing apps carrying the same components, after Norwegian security firm Mnemonic traced proxy code from Bright Data inside a Pac-Man game the manufacturer had promoted in its Editor's Choice section.
The statement, issued to TechCrunch after the publication approached the company about research published today, commitsย Samsungย to a platform-wide developer policy change across Tizen, the operating system that runs its televisions. It arrives thirteen days afterย LGย Electronics USA made a comparable commitment for webOS, and roughly a month after the first published measurement of how widespread the practice had become on both platforms.
What the code does
Aย residential proxyย network rents out the internet connections of ordinary households. Traffic from a paying customer enters the network and leaves through a consumer device, arriving at its destination with a residential IP address attached rather than one belonging to a data centre. Within the industry the shorthand is resproxy, and the enlisted device is described as anย exit node.
The research by Mnemonic, an offensive security consultancy based in Norway, describes what happens when that arrangement is embedded in television software. According to the report, apps containing resproxy code can convert a Samsung smart TV into an always-on tunnel for outsiders, and the tunnel continues to operate after the app itself has been closed. Some of the affected apps claim installation counts in the hundreds of millions, according to figures published by their own developers.
The mechanism that allows this to pass review is structural rather than technical. Many of the apps are shells of a few lines of code whose only function is to load content hosted elsewhere. An app store reviewer inspecting the submission sees the wrapper. The behaviour lives on a remote server.
“What was reviewed…
