Security expert Amihai Neiderman says he's found 40 zero-day flaws in Tizen, Samsung's OS that runs on phones, smartwatches, and over 30M smart TVs
but it's even more buggy. http://motherboard.vice.com/ ... J-Strizzle / @jstrauss : Exploding phones and now this. I think iPhone is safe from competition for a while (& Samsung should invest in QA) http://www.techmeme.com/...
Context & Ripple Effects
Samsung spent late 2015 marketing Tizen as a hardened platform, announcing its GAIA security stack with pin locks, encryption, and anti-malware for its new TV line. Within sixteen months, researcher Amihai Neiderman is reporting 40 zero-day flaws across an OS that ships on phones, watches, and more than 30 million smart TVs — and a separate team has already demoed a remote exploit against fully-updated Samsung TVs via a malicious broadcast signal.
The finding lands on a company whose security record keeps generating headlines: from the SmartThings Hub bugs that exposed smart locks and cameras, to the ~100M Galaxy phones shipped with cryptographic-key design flaws, to Google Project Zero's later Exynos chipset disclosures. The through-line is that Samsung's device breadth has outpaced its ability to secure the software underneath it.
First-order effects
- Samsung faces patching pressure across every Tizen surface at once — TVs, phones, and watches — since any fix must reach tens of millions of already-deployed sets that consumers rarely think of as updatable computers.
- Neiderman's disclosure hands Samsung's rivals a concrete talking point at exactly the moment the company is positioning Tizen TVs for content and app partnerships.
Second-order effects
- The SmartThings ecosystem inherits the reputational damage: if the TV OS is this porous, buyers of connected locks and cameras have reason to question the whole Samsung smart-home stack.
- Retailers and carriers carrying Samsung hardware gain leverage to demand faster, verifiable patch commitments before the next flagship cycle.
Third-order effects
- If the pattern holds — GAIA promises in 2015, 40 zero-days in 2017, key-extraction flaws in 2022, Project Zero findings in 2023 — the structural lesson is that scale without a disciplined security-development process turns every shipped device into standing liability, inviting regulators to treat consumer IoT patching as a compliance requirement rather than a courtesy.
The trend: Consumer device makers are learning that shipping one OS across tens of millions of screens converts every unpatched flaw into a fleet-wide liability, pushing IoT security toward regulated, auditable update practices.