When you connect a new LG monitor to Windows 11, the system does something you did not authorize—Windows Update delivers the LG Monitor App Installer without a permission prompt, without a notification, without a choice. The installer then drops McAfee advertisements directly into your machine.
You own the monitor. You own the computer.
This happened before. In January 2015, Lenovo shipped the ThinkPad X1 Carbon with Superfish pre-installed—adware that intercepted encrypted HTTPS traffic and injected advertisements into websites you were visiting. It decrypted your secure connections to banks and email providers, and it did this silently.
When security researchers discovered what was happening, Lenovo claimed it was just a bundling deal with a third party. The outrage triggered Congressional letters. Microsoft promised it would fix the mechanism that made this possible—Windows Update would be reformed, driver and firmware distribution would require explicit consent per item installed. That was nine years ago.
The system does not reform itself.
”Windows Update still permits original equipment manufacturers to bundle software into driver packages. The consent architecture still stops at "you connected a device" rather than "you want this specific software." The institutional vulnerability survived the scandal because the scandal never touched the institution's actual practice, only its public relations. Lenovo's lesson was supposed to be about transparency. What Microsoft actually learned was about damage control—the system works until someone documents it. Once documented it becomes a story about one company rather than an architecture that was always designed this way.
What matters now is whether the people who make intentional choices in their lives have learned a different lesson. If you are building something with deliberation, you probably already know the pattern. The system does not reform itself. It waits for the scandal to fade, then operates exactly as it did before under a slightly different name. You see this in your own work when legacy processes stay embedded inside new structures, when consent becomes a checkbox you stopped reading, when permissions get stacked three layers deep so compliance becomes impossible.