Samsung bans proxy SDKs: your IP is the product
A quarter of Samsung Tizen apps routed strangers' traffic through owners' home connections. Audit what your network's smart devices actually do.
Samsung is banning residential proxy SDKs from its Tizen smart TV app store after researchers found the code inside apps the company itself had promoted. If you're wondering why a TV matters to a business: the same SDK category ships inside free mobile apps, browser extensions, and VPN clients. Someone else's traffic exits through your IP address, and your IP address is what everyone else uses to decide whether to trust you.
What actually happened
Norwegian security firm mnemonic pulled apart a Samsung TV's internals and traced proxy code inside a Pac-Man game that Samsung had featured in its "Editor's Choice" section. The SDK came from Bright Data, an Israel-based proxy provider. Researcher Harrison Sand observed the resulting traffic being used for LinkedIn scraping and AI training-data collection.
The scale number comes from a separate scan by Spur Intelligence: 26.9% of all Samsung Tizen store apps carried residential proxy code, per TechCrunch's reporting on August 3. Samsung says it has restricted new app registrations containing proxy functionality, is writing a platform-wide developer policy banning the SDKs outright, and is removing existing apps that carry them.
Samsung is second here. LG announced the same ban in July after Spur found the SDKs in over 42% of its app store.
Why your IP address matters for your business
This isn't a TV problem. It's a monetization model: an app developer takes a check to embed an SDK, and the SDK rents out the device's internet connection. Nothing is stolen, nothing crashes, and the user never sees it.
The cost lands on your network's reputation. When a stranger's traffic exits through your office or storefront IP, that IP starts appearing in scraping logs, credential-stuffing attempts, and fraud-scoring databases. What that looks like from your desk: your payment processor flags your own admin logins, your email starts landing in spam, a vendor portal blocks you, or Cloudflare CAPTCHAs your team all day. You'll debug it as a networking problem for a week before anyone thinks to check the TV in the lobby.
Concrete moves that take an afternoon:
- Put untrusted devices on their own VLAN or guest network. TVs, cameras, tablets, the digital menu board. Same reasoning as keeping your office camera off the network that matters.
- Check your business IPs against a reputation service. If you're on a blocklist you didn't earn, you now know why.
- Treat free apps on business hardware as a supply-chain decision. "Free" has a revenue model, and sometimes the revenue model is your bandwidth.
- Watch egress volume, not just inbound. A TV that streams nothing but pushes gigabytes is telling you something.
Key takeaways
- Samsung is banning residential proxy SDKs from Tizen after mnemonic found Bright Data proxy code in a featured Pac-Man app
- Spur Intelligence measured the code in 26.9% of Samsung Tizen apps; LG banned the same SDKs in July after a 42%+ finding
- Strangers' traffic exiting your IP damages your network's reputation — spam filtering, fraud scores, and CAPTCHAs are the symptoms
- Segment smart devices onto their own network and check your business IPs against a reputation service
Most "our email stopped working" tickets are really infrastructure tickets. We audit the network and vendor stack behind your storefront and back office — tell us what's been breaking.
Sources: mnemonic, TechCrunch, Krebs on Security.
- #security
- #network
- #iot
- #supply-chain
- #privacy
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Superblocks and AWS: AI apps that run in your own VPC
AWS is embedding Superblocks' vibe-coding platform inside customer VPCs, with Aurora and Bedrock in your own account. The deployment model is the news, not the AI.
Read itTLS 1.2 is frozen: post-quantum ships only in TLS 1.3
The IETF published RFC 9851 putting TLS 1.2 in feature freeze. Post-quantum crypto will never be specified for it. Here's how to find what in your stack is stuck.
Read it