Deshittification Part 2: Bypassing the App Store Gatekeeper

Deshittification Part 2: Bypassing the App Store Gatekeeper

去垃圾化(Deshittification)第二部:绕过应用商店的守门人

Table of Contents by: Lari Huttunen 目录作者:Lari Huttunen

In my previous post, Deshittification as a Service, I shared a blueprint for taking back control from modern Smart TVs. I placed an LG OLED running WebOS inside an isolated VLAN behind an OpenBSD gateway. My goal was simple. I wanted to block vendor telemetry, strip out ads, and force the TV to act like a plain display again. I expected the hardware to respect these new boundaries. Instead, WebOS staged an uprising. As soon as I blocked LG’s Automatic Content Recognition (ACR) and ad servers at the DNS level, the OS fought back. It did not just drop telemetry packets in silence. Instead, it actively broke core system features. WebOS locked down the app store, threw cryptic error codes, and held basic app management hostage until the TV got unrestricted access to its tracking servers. This post documents how LG WebOS enforces an artificial telemetry toll booth at the app store layer. I will break down why this is a clear case of forced consent under GDPR Article 7(4) and show how to systematically document and challenge the gatekeeper.

在我上一篇文章《作为服务的去垃圾化》(Deshittification as a Service)中,我分享了一份从现代智能电视手中夺回控制权的蓝图。我将一台运行 WebOS 的 LG OLED 电视放置在一个位于 OpenBSD 网关后的隔离 VLAN 中。我的目标很简单:我想屏蔽厂商的遥测数据,剔除广告,并强迫电视回归到纯粹显示器的功能。我原以为硬件会尊重这些新的边界,但 WebOS 却发动了“起义”。当我刚在 DNS 层面屏蔽了 LG 的自动内容识别(ACR)和广告服务器后,操作系统便开始反击。它并没有默默丢弃遥测数据包,而是主动破坏了核心系统功能。WebOS 锁定了应用商店,抛出晦涩的错误代码,并将基础的应用管理作为人质,直到电视获得对其追踪服务器的无限制访问权限。本文记录了 LG WebOS 如何在应用商店层级强制设置一个人为的“遥测收费站”。我将剖析为何这属于 GDPR 第 7 条第 4 款下典型的“强制同意”案例,并展示如何系统性地记录并挑战这一守门人。

The Hostage Situation: Error E5.48.XV

人质危机:错误代码 E5.48.XV

To test how WebOS handles app management without telemetry, I needed a clean scenario. I decided to uninstall a core app first. Removing an app on WebOS is easy enough. I opened the edit menu and selected Netflix. I confirmed the prompt and deleted the application. I deleted Netflix, expecting to simply download it again from the LG Content Store. That is when the gatekeeper stepped in. When I opened the LG Content Store, the screen stayed black for a moment. Then it threw a cryptic error. Error code E5.48.XV claimed the service was “temporarily unavailable”. That was a lie. The TV had a working internet connection. The built-in web browser worked fine. Pre-installed local apps like Yle Areena streamed without any issues. The only broken feature was the app store. This was an artificial barrier. The operating system refused to show me the app store catalog because it could not talk to its tracking servers.

为了测试 WebOS 在没有遥测数据的情况下如何处理应用管理,我需要一个干净的测试场景。我决定先卸载一个核心应用。在 WebOS 上删除应用非常简单:我打开编辑菜单,选中 Netflix,确认提示后删除了该应用。我删除了 Netflix,本以为可以轻松地从 LG 内容商店重新下载它。就在这时,守门人介入了。当我打开 LG 内容商店时,屏幕黑了一会儿,随后抛出一个晦涩的错误。错误代码 E5.48.XV 声称服务“暂时不可用”。这是谎言。电视的网络连接是正常的,内置网页浏览器运行良好,预装的本地应用(如 Yle Areena)也能正常播放。唯一损坏的功能就是应用商店。这是一个人为设置的障碍。操作系统拒绝向我展示应用商店目录,仅仅因为它无法连接到其追踪服务器。

Decoupling the Store: The Artificial Toll Booth

解耦商店:人为的收费站

To see why the app store was locked, I turned to my gateway logs. I ran a live trace on my Unbound DNS resolver while trying to open the store. The TV (10.2.0.10) did not check a neutral status endpoint or attempt to reach an app repository first. Instead, it immediately hammered LG’s tracking and advertising domains. My local resolver (10.2.0.1) returned an instant NXDomain response for each request:

为了弄清应用商店为何被锁定,我查看了网关日志。在尝试打开商店时,我对 Unbound DNS 解析器进行了实时追踪。电视(10.2.0.10)并没有先检查一个中立的状态端点,也没有尝试连接应用仓库,而是立即疯狂请求 LG 的追踪和广告域名。我的本地解析器(10.2.0.1)对每个请求都立即返回了 NXDomain(域名不存在)响应:

2026-09-19 08:11:43.486 | NET: 10.2.0.1 -> 10.2.0.10 | Standard query response 0xf98e No such name A FI.tv.wiselg.com
2026-09-19 08:11:43.486 | NET: 10.2.0.1 -> 10.2.0.10 | Standard query response 0x8925 No such name AAAA FI.tv.wiselg.com
2026-09-19 08:11:53.484 | NET: 10.2.0.1 -> 10.2.0.10 | Standard query response 0xb868 No such name A FI.tv.wiselg.com

This log reveals a crucial architectural detail through what is missing. The TV never even attempts to contact the content delivery networks that actually host the apps. Instead of looking for software packages, WebOS inserts a mandatory pre-flight telemetry check directly in front of the store UI. If wiselg.com fails to resolve, the operating system aborts the entire app store sequence before it even begins. The lockdown is a purely artificial gatekeeping function. It is built to prevent you from managing your own software unless you let LG log your viewing habits.

这份日志通过“缺失的内容”揭示了一个关键的架构细节:电视甚至从未尝试联系真正托管应用的 CDN(内容分发网络)。WebOS 没有去寻找软件包,而是在商店 UI 之前强制插入了一个预检遥测检查。如果 wiselg.com 无法解析,操作系统会在应用商店流程开始前就直接终止。这种锁定是一种纯粹人为的守门功能,其目的就是为了防止你在不让 LG 记录观看习惯的情况下管理自己的软件。

Paying the Toll to Win the Battle

付费过路以赢得战斗

To prove that the App Store lockdown is entirely artificial, I ran an experiment. I temporarily paused my DNS blocklist on Unbound. I allowed LG’s tracking domains through the firewall for two minutes. The effect was instantaneous. The LG Content Store opened without complaint. I searched for Netflix, clicked install, and the app downloaded in seconds. I launched Netflix, signed in, and verified that video streaming worked in full 4K. Then I re-enabled the DNS blocks on my gateway. Immediately, opening the App Store failed again with error E5.48.XV. But Netflix was now installed on the home screen. Netflix continued to stream perfectly for a while, even with wiselg.com blocked. Video playback itself had zero technical dependence on LG’s telemetry. That peace was temporary. It was only a matter of time before WebOS’s background block detection kicked in and interrupted the stream. This experiment proved two iron-clad facts:

  1. Third-party streaming apps have zero technical dependency on LG’s tracking servers.
  2. The App Store lockout and subsequent stream interruptions are independent gatekeeping mechanisms enforced purely by WebOS.

为了证明应用商店的锁定完全是人为的,我做了一个实验。我暂时暂停了 Unbound 上的 DNS 黑名单,允许 LG 的追踪域名通过防火墙两分钟。效果立竿见影:LG 内容商店毫无怨言地打开了。我搜索 Netflix,点击安装,应用在几秒钟内就下载完成了。我启动 Netflix,登录并验证了视频流可以以 4K 画质正常播放。随后,我重新启用了网关上的 DNS 屏蔽。立刻,打开应用商店再次失败,报错 E5.48.XV。但 Netflix 此时已经安装在主屏幕上了。即使在 wiselg.com 被屏蔽的情况下,Netflix 依然能完美播放一段时间。视频播放本身在技术上完全不依赖 LG 的遥测数据。这种平静是暂时的,WebOS 的后台屏蔽检测迟早会介入并中断流媒体。这个实验证明了两个铁一般的事实:

  1. 第三方流媒体应用在技术上完全不依赖 LG 的追踪服务器。
  2. 应用商店的锁定和随后的流媒体中断,是 WebOS 纯粹为了守门而强制执行的独立机制。

GDPR 视角:强制同意

This design is not just user-hostile. It is most likely illegal in the European Union. Under GDPR Article 7(4), consent must be freely given. In plain terms, a company cannot hold a basic service hostage to force you into data collection. If data processing is not strictly necessary to deliver a service, bundling the two together violates EU law. Downloading an app binary from a server has nothing to do with screen hashing or ad profiling. The app store has no technical dependence on wiselg.com. LG uses the app store as a gatekeeper to force consent. If you do not let them track you, they disable basic features on your TV. Instead of accepting this, I took action. I compiled the DNS logs and filed a formal GDPR complaint directly with LG’s Data Protection Officer (DPO).

这种设计不仅是对用户不友好,在欧盟很可能还是违法的。根据 GDPR 第 7 条第 4 款,同意必须是“自由给予的”。简单来说,公司不能将基础服务作为人质来强迫你接受数据收集。如果数据处理对于提供服务并非绝对必要,那么将两者捆绑在一起就违反了欧盟法律。从服务器下载应用二进制文件与屏幕哈希或广告画像毫无关系。应用商店在技术上并不依赖 wiselg.com。LG 将应用商店作为守门人来强制获取同意:如果你不让他们追踪你,他们就会禁用你电视上的基础功能。我没有接受这种现状,而是采取了行动。我整理了 DNS 日志,并直接向 LG 的数据保护官(DPO)提交了正式的 GDPR 投诉。

下一个障碍:冷启动同意陷阱

Bypassing the App Store gatekeeper to install Netflix felt like a solid win. Watching 4K video stream smoothly on a locked-down TV made it seem like the battle was over. That victory was short-lived. Blocking the app store was just the entry-level penalty. The moment I power-cycled the TV and performed a hard boot, WebOS revealed its next line of defense. WebOS contains a hidden boot-time kill switch. If the TV boots up without reaching its telemetry servers, it enters a hostile state. It does not just block app installs. It a…

绕过应用商店守门人安装 Netflix 感觉是一场彻底的胜利。看着 4K 视频在被锁定的电视上流畅播放,似乎战斗已经结束。但这场胜利是短暂的。屏蔽应用商店只是入门级的惩罚。当我重启电视并进行冷启动时,WebOS 露出了它的下一道防线。WebOS 包含一个隐藏的开机“自毁开关”。如果电视在启动时无法连接到其遥测服务器,它就会进入一种敌对状态。它不仅会阻止应用安装,还会……