The Bug In Your Boardroom Came Bolted To The Wall And You Paid For It

A while back a client brought us in on the rollout of a new service they were proud of, especially their marketing team. They had purchased a large batch of smart TVs to put up across several of their locations. The idea was to have central control over what played on every screen so they could push wait times, new service offerings, and updates to their customers from one place instead of sending someone from IT site to site to update the old marketing displays.
They asked us to test the TVs before they went live. Two things came back that ended the project.
The first issue, the TVs were phoning home to a network in China. Out of the box, on their own, reaching back to infrastructure nobody in the IT department had ever heard of and nobody could account for.
The second issue, the TVs shipped with flaws that let anyone sitting on the same local network take control of them and change the messaging to whatever they wanted. We proved it. Their IT team balked at first, sure nobody could get onto the local network to pull it off. What they had glossed over was that their wireless ran on a single shared WPA2-PSK key bridged straight onto the wired network, so anyone with the Wi-Fi password was sitting on the same flat network as those TVs. We got on the network those devices used, pushed our own content onto the screens in the test environment, and owned what every customer in the building would have seen.
We never went after the cameras built into those units to turn them into observation points inside the client's locations. Not because we could not, and not because we were not curious how far it went, but because the moment we injected our own messaging the client had seen enough. They wanted the TVs pulled out.
Sit with that for a second. The device was a display. It was also a live channel back to a network in China, a takeover target for anyone on the same LAN, and a camera and microphone already sitting in the room.
This week that exact problem picked up a household name. LG got caught running a version of it at scale. Researchers found LG smart TVs, more than 200 million of them, scanning the local network and capturing room audio while sitting in standby with the screen off. In some cases the collection kept running with no internet connection at all. Logging interesting things locally and waiting for a connection. The lesson here really is that the screen on the wall is rarely just a screen. How many of us have smart TVs in our bedrooms. Let that one sink in.
Read what that TV actually is
Strip off the consumer angle and look at what you have hanging on the wall of the room where you talk about deals, layoffs, litigation, and strategy. It is a microphone with a network connection, aimed at your most sensitive conversations, that you purchased and installed yourself.
For as long as this trade has existed, a planted listening device was something an adversary had to sneak into a building and hide. Finding those devices is its own discipline, technical surveillance countermeasures. It exists because a hidden bug used to be hard to get into a room. That barrier is mostly gone now with the advent of smart technology. Now the bug ships from the factory, joins your Wi-Fi with your blessing, and pulls double duty as a foothold sitting on the same network segment as everything else.
Most teams miss this completely because of how the device gets classified. Your IT group logged that TV as a display. Your facilities group logged it as furniture. Nobody in the building logged it as what it is, a device that can hear your strategy discussion and reach your file server on the same night. We are one of the few shops that will sweep a room for surveillance devices and map the network for rogue endpoints in the same visit, and this is exactly why we do both. The eavesdropping problem and the network problem are the same device.
And do not put your faith in the settings menu. The toggle that says voice off or data collection off is a request to the manufacturer, not a guarantee. You are trusting the vendor's firmware to honor it. This week showed a major vendor's firmware doing the opposite of what its own menu promised.
What to actually do about it
Here is work you can run this week without waiting on a budget cycle.
Walk your sensitive rooms and inventory every device that has a microphone, a camera, or a network radio. That is the TV, the video bar, the conference camera, the smart speaker, the wireless presentation dongle, the digital assistant, and the smart display sitting in the conference room that nobody remembers buying. If it can hear, see, or connect, it goes on the list.
Put every one of those devices on a segmented network that has no path to your corporate systems. No route to the file server, no route to the domain controller, no route to anything that matters, and more importantly no route to the internet unless it is absolutely required. If that TV gets popped, the blast radius should stop at the TV.
Lock down what those devices are allowed to say. Block outbound traffic at the firewall to anything they do not strictly need, and watch the DNS and outbound connections coming off that segment. A display that is phoning home to a dozen destinations while the screen is black is telling you something.
For a conversation that truly cannot leak, stop trusting software. Pull the device out of the room or kill power at the wall. Device standby is not the power off switch. These units keep a live processor and a live radio running on standby power. This is how a black screen ends up scanning your network in the first place. A switched outlet or an unplugged cord is the only off you can prove.
Where the hardware allows it, physically disable the microphone and camera rather than relying on a menu setting. A hardware mic kill or a disconnected mic lead is worth more than any toggle in a firmware you do not control.
Write it into the procurement process. Consumer smart devices do not get installed in sensitive spaces without a security review first. The cheapest fix for this whole problem is not buying the surveillance device in the first place.
This goes deeper than one brand of TV
The lesson is that the line between an IT asset and a surveillance device is gone, and almost every smart screen, speaker, camera, and sensor in a sensitive space now sits on both sides of it at once. Each one is a microphone or a camera you can trust only as far as you trust a firmware you will never see the source code for, and each one is a live node sitting inside your network.
The uncomfortable part is that you invited every one of them in. Nobody had to defeat a lock or bypass a guard. The device came through the front door on a purchase order, got mounted by an installer, and joined the network during setup. Your device inventory and your countersurveillance posture are the same job now, whether your organization has noticed or not, and most have not.
Here is the question worth sitting with. You know what your firewall is doing. Do you know what the screen in your lobby is doing, who it answers to, and who else on your network can reach it. We caught a callback to China and a full takeover on hardware a client was days from trusting in front of every customer they had, and we caught it before it went live instead of after. Whatever is hanging on your walls right now, we will tell you exactly what it is doing, who it talks to, and how to shut the door. We would rather run that sweep this week than watch your name land in next week's roundup.




Comments