Skip to main content
Back to Blog
· 6 min read

The Hidden Horror of Connected TVs - ACR, Tracking, Botnets, and the Case for Dumb Displays

Your smart TV is watching you, and not just when it is turned on. Every major television manufacturer in 2026 ships devices with Always-on surveillance features that fingerprint your viewing habits, relay third-party traffic through your home network, and resist every attempt you make to disable them. The worst part: most of these features are enabled by default, buried under layers of settings that change with each firmware update.

Automatic Content Recognition: The Core Problem

ACR (Automatic Content Recognition) is the mechanism at the heart of smart TV surveillance. Your television captures screenshots or analyzes video frames multiple times per second, potentially thousands of times per hour, of everything displayed on screen. This includes cable broadcasts, streaming apps, Blu-ray playback, game consoles, and anything connected via HDMI.

Each frame is fingerprinted and sent to manufacturer clouds and third-party data brokers. The result is a precise behavioral profile: what you watch, when you watch it, how long you watch, and even what you skip. This data feeds directly into targeted advertising pipelines worth billions in annual revenue.

Why ACR is particularly dangerous:

  • It works silently. Most users never see a prompt or notification when ACR activates.
  • It is on by default. You must actively find and disable it during or after setup.
  • It covers everything. Unlike app-level tracking, ACR captures content from every source connected to the TV.
  • Firmware updates re-enable it. Multiple 2025 and 2026 reports confirm that Samsung and LG push updates that reset privacy settings to their defaults.

Even with ACR disabled, hidden telemetry continues to phone home with device IDs, IP addresses, viewing durations, and app usage. Full isolation requires more than toggling a setting.

How to Disable ACR and Tracking (By Brand)

Disable these features immediately during or after initial TV setup. Do not wait.

Samsung (Tizen): Navigate to General and Privacy. Uncheck Viewing Information Services and Interest-Based Advertising.

LG (webOS): Go to General, then System, then Additional Settings. Turn OFF Live Plus (the main ACR toggle) and Viewing Information. Disable ad tracking and personalized recommendations.

Roku, TCL, Hisense: Open Privacy, then Smart TV Experience. Turn OFF Use Info from TV Inputs and disable personalized ads.

Sony: Disable Samba Interactive TV and turn off ad personalization in the privacy settings.

Amazon Fire TV: Open Privacy Settings. Turn OFF Automatic Content Recognition, usage data collection, and interest-based ads. Reset your Advertising ID.

For all brands, disable: ACR, viewing history collection, diagnostics and usage data, voice and microphone access, personalized ads and recommendations, automatic updates (where possible), Bluetooth discovery, and third-party data-sharing agreements. Re-check every setting after any firmware update, as manufacturers routinely reset them.

These steps reduce exposure but cannot eliminate it entirely. The TV's operating system itself maintains telemetry channels that persist even with all visible options disabled.

Brand Risk Overview (2026)

Highest risk: Samsung, LG, Vizio, and Roku-powered TVs feature deep ACR integration, aggressive data monetization, and residential proxy SDKs embedded in their apps.

Moderate risk: TCL and Hisense collect less data than the leaders but still ship with ACR enabled by default.

Relatively better: Sony offers more granular opt-outs and does not embed proxy SDKs in its built-in apps.

Best practice: Do not rely on any smart TV's built-in features for daily use. Treat the TV as a display only.

Botnets, Proxyware, and Exploitation

Always-on smart TVs are prime targets for botnet recruitment. Their constant uptime, infrequent security auditing, and unpatched vulnerabilities make them attractive to operators seeking to proxy traffic through residential IP addresses.

Many LG and Samsung smart TV apps include residential proxy SDKs that relay third-party traffic through your home IP address, often without meaningful consent. The consequences include:

  • IP abuse: Your IP address is associated with activity you did not perform, including potential abuse targeting other networks.
  • Network pivots: A compromised TV provides a foothold into your entire home network.
  • Bandwidth theft: Proxy traffic consumes your upload and download capacity.
  • Legal exposure: Activity routed through your IP can generate legal inquiries directed at you.

The fundamental question is straightforward: why connect a display panel to the internet with opaque, unauditable software? Intelligence and connectivity belong on devices you control, not on a TV with hidden backchannels.

For Large TVs: Never Connect Directly

For screens 55 inches and above, choose a dumb (non-smart) TV panel or keep any smart model completely offline:

  • Unplug or disable WiFi and Ethernet permanently.
  • Disable all network features, ACR, voice services, updates, recommendations, diagnostics, and sharing agreements.
  • Use only external HDMI sources for content.

This setup maintains full picture quality while eliminating cloud-based risks entirely.

The Better Solution: PC Monitor as TV

The strongest privacy approach for a living room or bedroom is a 30 to 43 inch 4K PC monitor used as a television. PC monitors have no operating system, no WiFi, no smart features, and no tracking of any kind. You get a sharp 4K panel with zero native surveillance.

Pair the monitor with a trusted external source. An Apple TV 4K offers a clean privacy profile and polished media experience. Alternatively, a mini PC running a hardened setup gives you full control.

The Ideal Privacy-Focused Media Setup

  • Display: Large 4K PC monitor connected via HDMI. No smart features, no network stack, no tracking.
  • Core device: Mini PC running a hardened firewall and router (OPNsense or pfSense) alongside media capabilities. Strict firewall rules with network segmentation, robust DNS blocking for trackers and ads, and an always-on VPN with kill switch and traffic obfuscation.
  • Media server: Jellyfin (self-hosted) for local media libraries and streaming. Add automation tools from the Arr suite for media management.
  • Hardening: Full disk encryption, minimal running services, active logging and regular audits, encrypted backups on local storage and a secure cloud provider with encrypted vaults.
  • Workflow: All content routes through the mini PC or Apple TV. The monitor stays completely passive with no internet connection of its own.

This configuration delivers full 4K entertainment: streaming, local media playback, and gaming, with maximum control and minimal external exposure.

Bottom line

Reject the premise that a television needs an internet connection, a microphone, and a software stack you cannot audit. A passive, high-quality monitor powered by your own secured sources is the privacy gold standard for home entertainment in 2026. The surveillance built into smart TVs is not a bug; it is the business model. The only winning move is not to play.