72% of smart TVs and 46% of game consoles hardcode DNS settings
labzilla.io
labzilla.io
Please, if you have a Pihole, redirect all DNS through it as described in the article. Just be aware DNS over HTTPS is a thing now, and while the devices I’m responsible for aren’t going to try and evade your redirects, the companies that are trying to make sure ads get delivered will absolutely switch to DoH which will be much more difficult to work around.
I am very suspicious of the push for https and the like. I feel it is mainly about hiding the payload from me not any third party.
You might control the resolver on your personal computer (for now). You probably don't control it on your phone. You most likely won't control it on your embedded devices.
If it doesn't see internet it just blocks itself and goes to a screen "Oops I have no internet".
So you can forget about watching movies from your local server using the VLC app as well. Ridiculous.
I think it's insane that devices can effectively be bricked if they can't phone home. It's nothing short of waste, and I think environmental legislation should require device manufacturers to supply ways of disabling or overriding these mechanisms such that devices can continue to operate regardless of whether home servers are blocked or otherwise out of reach, e.g. company goes belly up, censorship etc.
Actually you probably should return such devices as broken.
It was kind of hard to send back a really nice device that I had just opened up and was ready to fly.
Thing is, some companies just use it as a way to fire their customers.
However, they are also playing these sorts of games with other types of devices, where no such justifications exist ( https://www.eevblog.com/forum/eevblab/eevblab-83-dji-pocket-... ) That needs to be answered by returning the product as defective.
I will admit I haven’t done any further investigation, but simply concluded that the gateway at some point started phoning home and if it didn’t receive a response went into some catatonic state. Maybe I’ll dig deeper at some point, time permitting.
Using DoH, especially one served by an advert company is just signing up to be their open book.
Hold up. You are claiming that the fact that DoH prevents DNS requests from being visible in cleartext network traffic is a bad thing?
...what? In a world where the choice is between one party (the DNS provider) having access to my DNS requests and everyone on the network including my DNS provider having access to my DNS requests, I'll choose "DNS provider having exclusive access" every single time.
It is when its my network. If they cared about people sniffing they would use DNSSEC, but still use the network DNS server. DNS over HTTPS is just a way for shady companies to hide what they're doing.
The problem of shitty devices on your private network is a different one.
I recently bought a car, and could not find one without a cellular modem and microphones. Removing the modem voids the warranty. The period where you can opt out is mostly over.
For the manufacturer to avoid a warranty claim due to a modification or aftermarket part, they must show that the defect was linked to the part or modification.
They might have to show that it was caused by, but in any case, if your paint fails prematurely, they can’t say your warranty is void because you disabled the cell connection.
Otherwise it is probably mostly equal to driving without registration. It may not be a felony, but it will be fined.
Somewhat more sophisticated would be hardcoding an IP to a server with a REST endpoint that returns the real final IP. (Basically just like what DoH does, but without calling it DoH).
Even more sophisticated would be hiding the final IP on some kind of public web service like Twitter or Github.
These devices do usually have an UI. Why not provide some options to the user? Let him choose among different types and providers. I'd set mine to use the one provided by DHCP or enter the address of my resolver manually.
In my experience, product design is generally done with a well-meaning attempt to protect the average user from themselves. People who can and do manage their own networks in sophisticated ways are, unfortunately, far less common than people who have no idea that their ISP fscks with DNS lookups.
Personally, I'd bury this setting pretty deep in an advanced-usage-only tab and behind a notice SCREAMING about how using these settings is unsupported. And then tell support staff that they are not obligated to support whatever crazy configurations people cook up for their home networks.
I understand not doing it at all. A few people will complain, but the number of people who will refuse to buy a TV because it doesn't play nice with their pihole is almost certainly too small to register on any material financial statement, and attempting to please them will generally run into some other point they are unwilling to budge on. The number of people who screw up an advanced setting they don't understand will show up in support costs.
The way we solve this is that we assume any knowledge the device has about the outside world can become obsolete, so we do we have a two layer approach.
The bottom layer is that we have a set of semi hard-coded fallback values that are likely to work in the forseeable future. Updating these fallbacks requires an over the air firmware upgrade which isn't a terribly big deal since we regularly upgrade firmware over the air. The goal of these values is to make sure we can get the device online and direct it to somewhere where we can trigger firmware updates.
The second layer is that one or more times per day we ping a config server that sends a packet with configuration data to the unit. This is typically API endpoints etc. The configuration data is essentially a prioritized list of resources, so if one won't respond it will go to the next on the list (while still trying to determine if a higher priority resource becomes available).
Last week we got a chance to see how this failed over beautifully as multiple resources were removed and a fleet of devices just adapted as they should. (The shutdown of these resources were planned, but presented a good opportunity to do a fire drill).
I can see myself using it as well, maybe even just to see which devices don't use DNS.
Here's another idea: generate a unique IPv6 address per DNS request, route them to the correct destination, filter other IPs. Not really scalable, but usable on small networks/VLANs.
Why wait?
Netgear, at one point, also decided that hard-coding an IP address (for NTP, not DNS) was the best solution [0].
--
[0]: https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse#Ne...
As opposed to the IP addresses that your DHCP server told you about.
I wonder who's the first sponsor for that thing, dns-over-https...
Universally? Perhaps in the US? But IoT devices are sold worldwide.
While I do run my own recursive resolver I checked my ISP's and they're behaving fairly reasonable and do none of the above and I have a direct (contractual) relationship with them and we reside in the same jurisdiction so at least in principle I could apply pressure to them if they do something shady. The same can't be said about google or cloudflare.
> Just be aware DNS over HTTPS is a thing now, and while the devices I’m responsible for aren’t going to try and evade your redirects, the companies that are trying to make sure ads get delivered will absolutely switch to DoH which will be much more difficult to work around.
I'm sure google had only our best interests in mind when unleashing that on us.
Before going with the conspiratorial take note that Mozilla shipped DoH early and both Microsoft and Apple implemented it. Untrustworthy ISPs are a real problem even if Google deservedly gets suspicion about their motives. This isn’t another AMP.
and DoH is absolutely designed to get around network based security and filtering, both for Ad's and other reasons.
You can just say you don’t follow this closely. Mozilla is not perfect but they do push for privacy, with an increasingly limited amount of negotiating power.
> DoH is absolutely designed to get around network based security and filtering, both for Ad's and other reasons.
This is similarly reflecting a poor understanding of the situation. DoH can’t get around network filtering - if you block packets, there’s no magic trick to bypass it. It’s great for preventing ISPs from tampering with traffic or monitoring activity (this will also require eSNI to complete) but it’s not giving an attacker any capability they didn’t already have. If you’re concerned about security you’re fooling yourself if you don’t have endpoint management and some level of network segmentation and egress control. Attackers have hard-coded DNS servers, C&C endpoints, etc. for decades.
The point of the original story is "your" meaning a device you own, is ignoring your network controls
it is highly unlikely that the TV manufacturer is going to allow me to install my own custom root certs to inspect their traffic to HTTPS, so yes DoH and other things are a threat to network security, because if the TV become compromised I have limited administrative controls to prevent it other the blocking it completely which is a poor response to the problem
DoH is a solution in search of a problem that can be solves in better more user friendly ways
The usual approach to setting up a firewall is a default of "block everything" and then selectively allow only what is needed.
Most people cheat and only do this on inbound connections, allowing everything on the egress side, because it's easier. But if you want to block your IoT devices from making outbound https connections, you easily can.
There's nothing really new going on here. It's always been possible to tunnel one protocol over another, or use nonstandard ports, and use encryption on the traffic to hide what you're doing.
For this reason I wouldn't recommend buying a device like the Chromecast, in which the user can't configure the network settings. Instead maybe consider something like the Amazon Fire Stick which is not as user-hostile.
I would also love to MitM myself in some cases, mostly because it’d be interesting to see what’s going on.
So before applying that mentality, it would be wise to consider what your experience would be like if all your neighbours, friends, colleagues etc also did that on their networks.
The solution is to start doing network filtering: if you block packets to unapproved servers, you can actually stop this. You’ll need to run your own proxy, of course, but that’s always been the only way to actually accomplish that goal.
Of course, jailbreaking opens up other security issues, so it goes back to what you can tolerate.
[0] https://checkrain.org/ [1] https://letsencrypt.org/getting-started/
I would imagine you can use this to push any certificate that you can also push to an iOS/iPadOS/macOS device.
This is a very good point and I am dealing with this myself on my home networks.
Like any household/family we have some number of dubious/untrusted devices that still need Internet access.
By establishing my own recursive resolver I can act as a chokepoint (and monitoring point) for their behavior online. It's a very elegant solution, actually, and I have created a nice integration between my datacenter-hosted resolver and nextdns.io as the adblocking upstream DNS.
DoH breaks all of this.
I have no interest in diving down the "MITM my own network by inserting custom certs into embedded devices that may or may not use them".
Since we're talking about it, though, it occurs to me that you could quickly do a DoH lookup to every single new IP connected to, outbound, from your network - and then block all IPs that answer your DoH query. You're basically pre-testing all new SSL connections to see if they are to a DoH resolver that you (presumably) don't want to talk to ...
This solves the CDN problem ... does it solve the problem entirely ? I have only just thought of this moments ago ...
This only works for the subset of devices which use the local DNS. If they use any of the well-known techniques to avoid that filtering it's completely ineffective.
> Since we're talking about it, though, it occurs to me that you could quickly do a DoH lookup to every single new IP that initiates a new connection, outbound, from your network - and then block all IPs that answer your DoH query.
It doesn't solve the CDN problem: CDNs will route traffic based on the hostname and blocking them will have a degree of collateral damage which most people can't work with. Setting up your own HTTPS proxy avoids this.
If you also block all port 53 after allowing your own resolver ... you may have some headaches with devices that refuse to use the DHCP provided resolvers but you know they aren't going to other resolvers.
That kind of control is what DoH breaks and I'd love to find an elegant (non-MITM proxy) solution for it ...
And in the context of pihole and such, avoiding that means editing the DNS response to remove those public keys. Which takes us full circle back to "do I control DNS for this gadget, or not".
Standard DNS is unencrypted. DNS-over-HTTP is encrypted. Or DNSSEC or any number of newer standards that secure the DNS lookup. At that point, filtering will require MITM proxies, whether it's for DNS or HTTP or any other protocol.
It's a trade-off with security on the open network meaning harder penetration and control in your internal network. There's no easy answer.
Why do you say it's not authenticated? If they're using the newer standards then that's what it provides. If they're not then there's no issue with network filtering as usual.
It doesn't matter if you're using your ISP's servers, 8.8.8.8, 1.1.1.1, or a custom server you set up on Digital Ocean somewhere: an on-path attacker can forge DNSSEC responses to you. It's a ridiculous situation.
The problem is that your relationship with your network devices is logically the same as a totalitarian country's/company's relationship with their citizens/users. So any protocol that prevents censorship/surveillance by ISPs also impinges upon bona fide network administrators. Corporate networks have the same dynamic, although there are few tears shed when it becomes harder for them to tamper with users' traffic.
The right answer is to make sure devices that have any Internet access run code you control. The root of the problem here is buying a "smart" TV, hooking it up to the network, and then expecting to tame all of its user-hostile anti-features by policing its communication. The only way to use black box IoT devices is to remove all general Internet access from them, allowing communication only with hosts you do control. For instance I've got a network of tp-link bulbs that are all controlled from a Home Assistant instance, and they never have and never will get a packet out to the larger Internet.
I agree that the core problem here is blocking egress entirely – and that’d be a good area for home routers to add UI polish so you could easily allow your TV to hit Samsung.com if there’s an update you need before turning it back off. Unfortunately that’s going to be a losing game for many devices and that really hits at the root cause: we need strong regulation controlling privacy because trying to stop a well-funded company with purely technical measures is almost always a losing game.
> hit Samsung.com if there’s an update you need
Why would you need an update? Updates are mainly necessary for security, which you don't need if the device isn't on the Internet. If the device doesn't have all the features you expect out of the box, return it within the return period. There's a small corner case where an update could carry significantly increased functionality, but it seems easier to ad-hoc address that down the line rather than plan for it. Carelessly doing updates is a good way to break your device.
> Unfortunately that’s going to be a losing game for many devices
I don't see how it's a losing game if you play it correctly. Fine grained policing of types of traffic is a losing game, but wholesale denying transit isn't. There is little difference between my network of tp-link bulbs and a local modbus network.
You've never had a problem which was fixed by an update or something which added support for, say, a new model peripheral? I have, which is why I allowed for the possibility of wanting to do this on the schedule of your choosing but not the default case.
> I don't see how it's a losing game if you play it correctly. Fine grained policing of types of traffic is a losing game, but wholesale denying transit isn't. There is little difference between my network of tp-link bulbs and say a local modbus network.
I was thinking less narrowly than devices which never need to be online. A TV connected to other players can run entirely offline but there are many other things which legitimately need connectivity and there's no good way to prevent that. For example, think about a device like a Chromecast or Fire TV, or those Facebook video chat appliances — people buy those to stream content so the most you can do is force the vendor to send marketing stuff through the same endpoint they use for your content, and that's increasingly hard to filter (think how useful a “it goes to an IP in AWS. Block y/n?” prompt is). That's why I said it'll require a legal fix since a large fraction of the most invasive devices either already do or could trivially be modified to mix other data in with the traffic needed to function.
For embedded devices? No. I can imagine it happening in general, but I don't think I would ever buy into a proprietary ecosystem so hard that there would be peripherals, and newly released ones at that. Still I would be cautious about doing said updates, lest they ruin the device I already have. Like I've got a newer Marantz receiver that works great and hasn't seen the Internet in several years. Even if they developed some new desirable feature, why would I want to let it reflash itself and possibly break, or even just get slower (software bloat)? I'd rather just continue using it as I bought it.
> there are many other things which legitimately need connectivity and there's no good way to prevent that
I sort things into categories. A TV would be in the category of "wtf would you ever hook that up online" - Internet access can only enable anti-features. A Chromecast is a different category - single purpose disposable device that if it turns into shit you just throw it out. Ads and surveillance are part of its price, and if your goal is to avoid them, you should just setup a Kodi box and call it a day.
Legally I don't really see what you're getting at here. I can see a law for my TV category, but leaving it disconnected or pulling the 5G modem will also solve that. How would you even begin to solve the Chromecast problem with a law? Maybe in the EU you could convince them to mandate unbundling ads from a service, but in the US exploiting consumers by shoving ads at them is one of the most popular business models. I don't see that ever changing via the legal system.
Follow the money .. watch the actions not the words
You’re going to have to make a more substantial argument to get anywhere with this.
As someone who has used (and still use Firefox) continously since around 2005 it surely feels that way sometimes and some of the decisions I see would make much more sense to me if I knew top management was somehow in Googles pocket.
(That said
1. for my workflows I still consider Firefox the best browser.
2. switching would only make it even easier for Google.
3. I always hope something will change and Firefox will become really really great again or someone will fork it.
Consider.
[0] https://en.wikipedia.org/wiki/Mozilla_Corporation#Google
[1] https://www.theverge.com/2020/8/15/21370020/mozilla-google-f...
There was a recent change to facebook picture albums that lazily loads pictures as you scroll. In large albums this grinds to a halt after a few pages and each scroll takes 30 seconds to load the next set of images. Chrome handles this smoothly. For social media I had to switch to chrome.
Firefox is still better for privacy and I use it when I can even though it feels like it's slowing down after each upgrade.
Abrowser (from trisquel) is what firefox should have been. Best fork out there imo.
Here's an article from November 19, 2020 about the rollout and some of the criticisms/backlash:
https://www.zdnet.com/article/fearing-drama-mozilla-opens-pu...
Ugh, the situation is even worst in countries with censorship laws. For example, in my country, all ISP are required to intercept all DNS requests and filter all requests to any blocked domains found in the government block list. At least they're transparent about which sites are blocked though (the list is publicly available to query or download), but the fact that all DNS requests are intercepted causes various technical issues and some ISP are trying to profit from it by redirecting the blocked query to their own ads-laden landing pages. They even went as far as inspecting http host header as well as randomly injecting scripts on unencrypted http requests.
DNS over HTTPS is an abomination sold as snake oil security.
Mozilla did more to unleash it than Google. Someone from Mozilla coauthored the RFC for it, and Mozilla had browser support for it first.
I was troubleshooting an issue where a company's client computers which connected to the company VPN wouldn't have internet access post-connection.
The problem turned out to be that instead of sending a NXDOMAIN they'd return their ad server and then _always_ send back some JS to show ads.
The company network used PAC files (these are a piece of JS with a single FindProxyForURL() function) via an internal-only URI to steer most requests to our proxies, while keeping some internal.
The problem came about when clients would first start up the OS would attempt to access the internal-only URI before the VPN client finished connecting. In a normal network it'd get nothing and life would carry on. With this problematic ISP they'd get something that /should/ have been a PAC file, but because it was some other piece of JS without FindProxyForURL() it wouldn't work as a PAC file and thus the client wouldn't go to the proxy.
The expiration on this piece of JS was set to some absurd amount of time, so when the client would eventually try hitting our PAC file server again (happens every 20 minutes on Windows) it wouldn't get our file because it thought the garbage one from the ISP was newer. And the ISP updated their hijacking JS more frequently than we updated our PAC file.
There were two possible solutions to this. One, routinely touch the PAC file so it's date was newer than whatever the ISP put out. Or two, set up an external A record for the internal PAC server name to keep the hijacking from working. We went with the second.
Laughably, DoH is from the same gang of A-record squatters that refused to incorporate SRV into HTTP on the (now very evidently spurious) grounds that it could, in some scenarios, require an extra packet, and they couldn't work out how to make it backwards compatible.
Having been comprehensively hijacked by the interests of advertising companies, my view of the HTTP WG has never been lower. And that's a shame because there are some smart people there, tasked with slowly eroding away the last semblance of end-to-end transparency.
The ISP provided DNS in South Korea is absolutely terrible too. Setting 1.1.1.1 or 8.8.8.8 always serves far better experience than the ISP's.
When you are contracted to build something to spec and you don’t build to spec, you don’t make any money. If you push back on the requested spec, the client will leave and go to another company thus leaving you without any money.
What I’m trying to say unless you are writing the spec, you usually have no chance to change anything
It boggles my mind it's still a problem in some countries. Last time I saw this kind of notice it was in the nineties, and on a web server, definitely not on a client endpoint. People have had unlimited bandwidth for at least a decade now.
https://old.reddit.com/r/homeautomation/comments/k72lzq/sowh...
[1]: https://github.com/bambenek/block-doh
[2]: https://github.com/Sekhan/TheGreatWall
Edit: I am mostly curious to see what devices/applications it will break.
If your hardware isn't resilient to network failures then it absolutely is your fault.
I've been running PiHole-like software on my network for a few years now. A couple of years ago, it would block over 40% of traffic consistently. I never saw ads, and it was nice.
In the last year, blocked traffic has dropped to about 15%, and I'm increasingly getting ads on my phone and Chromecast despite tunneling my traffic through my ad-blocked network and blocking Google's DNS at the network level.
Run 'update your block lists' on your Pihole to make sure the lists are being updated correctly.
I'm one of those "idiots" whose been whistling in the wind against encryption of everything and all kinds of security lockdowns and it's because of this sort of thing. The theoretical threat of someone sniffing my traffic is just not a concern to me compared to the very real and increasing threat of handing all control of my computing to centralized user-hostile powers.
And that along with DoH is contributing to making my life a pain in the butt. How exactly do you folks who avoid our DHCP's DNS expect us to comply with legal filtering requirements? Also, what happens when your hard coded DNS servers are shutdown?
I would argue that this is more a problem with the legal requirements than with the equipment - the law(maker) has expectations you can’t reasonably fulfill.
Doesn’t make your situation any better of course, the law is the law even when it’s impossible
Clear text DNS is the ultimate compromise, a gentleman's agreement if you want, that benefits everyone. We can see just enough to filter what we are required to by law on a best-effort basis, but we never see what you are actually doing thanks to the prevalence of TLS. DoH just broke that agreement.
It's a sad example of how a privacy solution like DoH will eventually result in less privacy, at least in some environments. And I'm not even considering how DoH will be the excuse for totalitarian regimes to up their surveillance antics.
I'm damn sure once I have to do the trusted CA path that someone is going to sell a deep packet inspection solution and present it at some conference where someone in charge will hear about it and then it will be off to the races.
Designing a device to connect to something over the internet even if the network it's connected to behaves strangely isn't random or stupid; it's just in conflict with your goals. Incidentally, last time I ran into a network with legally mandated filtering, I checked whether a google image search for "tits" worked. It did.
Nope, it behaves fine. The owner of the network is serving under age kids. Push too far and its white lists only and block all other IP and I'm sure we'll get deep packet inspection forced on us. Some folks have serious problems with Google Images Search, but you can actually deal with that.
I would also say anyone hard coding DNS into a device is just absolutely unprofessional. Its basically a red flag that any filtering the owner of the network doesn't matter to them.
I'm generally inclined to think an "always use this manually-configured DNS" option is desirable in that situation. Of course, many devices may have a financial incentive (ads) to actively resist the network owner's attempts at filtering.
Filtering is inherently adversarial, and I expect a reasonably sophisticated user on your network could find a way to access some proscribed content. I also expect the users of concern on your network are under five years old and that most of them lack advanced knowledge of networking. Is there an established standard for what qualifies as a reliable-enough filter?
Yet that is what internet actually is for a lot of people...
Many years ago, a old friend of mine purhcased a new Panasonic Smart TV. It was when "Smart TVs" were just becoming a thing.
I hooked her TV up for her; wiring it into the ATT uVerse modem directly. Other devices worked, but this one did not.
After resetting the modem, factory resetting TV, and making sure the ip address on the TV's menu were displaying properly and matched the router's config (they were), as a young naive tech nerd, I just said:
"Looks like they sold you a dud. Thankfully you kept the receipt!. Either way, you still have warranty to get it replaced."
My friend replied: "Shouldn't I call them first before taking it back?"
I said I didn't think it would help, but go ahead.
About 30 mins laters, she was talking to Panasonic tech support and they asked her to manually enter the DNS entries [I believe it was 75.75.. so Comcrap's], and voila, the TV was online again.
We were very happy it was an easy fix; but that day I deftinely did a LOT of reading on DNS servers.
Till this day, DNS entries are something I always check over when troubleshooting (as well as setting my router to Cloudfare's).
This is the list I use: https://public-dns.info/nameservers-all.txt
Conceivably, there's no need to it to even use "real" DNS at all, you could just run a server that responds to queries like "updateserver.ecorp" and save the hassle of even announcing these servers to the public DNS at all.
Also, DoH or not, there are plenty of other ways to ensure that ads get through a DNS filter. For example, a local hosts file could be included in firmware updates and they would just need to make extra effort to ensure that the server IPs didn't change (an elastic IP or load balancer in AWS would be all you need, then it can persist even if the VM has to be deleted).
As is DoT :)
Certainly in Europe I’ve not seen anything even close to that.
I’d love to see a good country-by-country survey on ISP DNS to see just how common this manipulation is.
The toxic ISP issue isn't so dramatic where I live, it used to be worse 15-20 years ago. But the solution has always been: if the ISP is messing with you, you just buy your own router and configure it for your network, with a VPN tunnel if necessary. Ignoring DHCP makes this unnecessarily harder.
TVs should be incredibly dumb. They should be screens for displaying stuff. That's it. Nothing else.
No network connection of any kind, no apps, no software beyond that necessary to do basic setup of how that screen works: brightness, input selection, etc.
It does, but only just. There are still a few models around, but the category of large-format dumb displays has virtually disappeared over the past decade. Commercial displays have almost entirely turned into smart TVs that run business apps instead of consumer apps.
Content Management/Group Management SuperSign Control Simple Network Management Protocol (SNMP) Wake-on-LAN Crestron Connected® (Network Based Control)“
That’s not a dumb TV
Quite honestly, by just airgapping your "smart" TV, you're effectively receiving a subsidy (as annoying as that may be)
[1] https://www.businessinsider.com/smart-tv-data-collection-adv...
Don't you think it's more manipulative to build a one-sided argument into the question?
Not sure how that plays out in practice, but not a distinction without a difference.
When I buy a computer monitor, I can pair it with any computer I want. I can upgrade the graphics card or processor independently of the monitor. I'm not locked in to a particular computer based on the features of the monitor I want. TVs should be the same. It could be as simple as a USB stick you plug in the back.
The implication here is that the connectivity tech goes obsolete quicker than screen tech. That has traditionally been true, but has it been over the last 5 years or so? We don't even have to get into the specific display technology. Just from a feature perspective, there has been a lot of innovation in screens including 4k, HDR, and high refresh rates.
Since the end of the digital-TV transition, the TV industry has been throwing a lot of stuff at the wall trying to find something that stuck. There's no clear "it becomes a paperweight" factor to make us all go out and replace newish sets right now. Remember the 3D TV trend? Or the year when everyone brought out curved sets, and then went back to flat? Smart TVs are another variation on that theme, with the added benefit for manufacturers that their lowest-bid tech and changing third-party service requirements will leave you with a set where half the hard-coded service buttons don't work and the other half are unusably slow to depress you into buying a new set in three years.
I expect the next real ecosystem change will be when ATSC 3.0 becomes a workable thing. Then you'll actually be able to offer 4K/HDR with an array of content without the caveat of "external game console/PC/streaming service required." I'd be a bit hesitant to get a new set until then just out of the risk you ended up with something not fully compliant (I'm thinking of those first-gen 4K LCDs that wouldn't accept a 60Hz input)
If you compare setups between a new TV with a few year old Roku, AppleTV, or whatever versus a few year old TV with a brand new streaming device, the setup with the new TV is likely going to be the superior option. In fact, Apple hasn't even released a new AppleTV since 2017. I have no idea if this will be a trend that continues, I just don't think "the streaming hardware becomes outdated quicker than the display hardware" is guaranteed to be true like we have assumed it was in the past.
TV display technology is likely to proceed in plateaus because they tie to agreed upon standards. By the mid 1990s we had the ability to make a 1600x1200 CRT monitor with a 85Hz refresh rate, but even a top-of-the-line TV wouldn't offer much more resolution or higher refresh than a 1965 model-- that's all you could get out of NTSC broadcasts. (Yeah. there were some progressive-scan input formats, but that's still only a token advance)
Introducing external sources (streaming, consoles, etc.) provides a bit of wiggle room to advance the resolution/colour/refresh rate bars, but that's still not going to change the installed base nearly as fast as if they said "here's a new standard format and every local broadcaster starts 8k broadcasts tomorrow."
In contrast, streaming products evolve in a continuous curve. Since there's very minimal, if any, platform standards, they can say "here's 24k resolution", or equally likely "here's a new codec/DRM format/API that old boxes don't support."
New streaming service comes out and there isn't an app for it on my device? Or security updates stop being pushed and now my device is part of a botnet? Now I care.
Your argument is that this adds value to the chromecast dumb tv pair, despite being a fundamentally destructive operation.
And that's how they get you.
I’d always chuckle thinking of the boogeyman bad actor employee who decided to exfiltrate customer data to a circa 1999 palm pilot at 9600 baud via IR instead of the dozens of easier methods available.
Do you mean to say you have a simple opinion?
At least my TV still allow firmware updates via USB, so you may not lose that. Not that it'd matter much if you weren't using any smart features, but they do still provide things like improving compatibility with devices (recently HDMI 2.1).
I have a bigger issue with VR headsets. They go a step farther in that you have to use their platform. There's no equivalent of "just use HDMI" in some cases.
Wait until they have TVs that connect to cellular which doesn't need your consent
Yeah I am so tired of hearing about 5G. Because that's exactly what it will be.
Furthermore, an external box is easy to replace when it breaks or becomes obsolete. What are you going to do when the embedded OS in your sly TV is no longer supported?
No thanks. My TV is a monitor, only. It has never been, nor will ever be, connected to my home network after I first brought it home and updated its firmware to whatever was current at the time.
https://old.reddit.com/r/netflix/comments/jq9wdb/netflix_cap...
TV makers are horrible software developers, for the same reasons that mobile manufacturers were horrible mobile OS developers until Android came along.
We have similar solutions for televisions in the form of Apple TV and Chromecast.
I honestly feel I’m wasting my money when I’m buying a smart TV these days, but you just narrow your choice so much if you only look for dumb phones, you’re almost forced into buying one.
I doubt it.
... at spying on you
Also, don't overestimate the bill of materials for a smart TV. Even a "dumb" TV almost certainly has silicon brain simply for controlling the settings UI and various other functions - that's cheaper than buttons, and remotes need something to talk to, so really, a smart TV simply means "a slightly fancier chip" - but still a chip that's several generations old by smartphone standards. It's not going to be a significant extra investment for the producer.
https://www.lg.com/us/business/commercial-tvs/lg-65ut640s0ua
Other TV manufacturers make similar products.
[1]https://needgap.com/problems/64-make-tv-dumb-again-privacy-c...
TL;DR buying enterprise grade gear of any substance from across the globe as a consumer is a little bit more involved than ordering a pair of slippers frome some seller on AliExpress.
* as in: beyond the next Wal-Mart
Of course, there’s also the simple thing of “enterprise stuff costs more for no reason.”
That "no reason" is usually a combination of the following:
1) Support avenues - commercial customers want rapid support in case something breaks, including overnight / on-site repair. That infrastructure costs more money compared to consumer appliances where the customers have to ship stuff to a central repair place.
2) Quality. Consumers are used to stuff failing after 3 years and get the next new hot thing, commercial customers want a decade or more in life span with as few maintenance calls as possible - and especially they don't want to redesign enclosures when the model is no longer available so they demand longer shipping times - again, on the order of 10 years or more. Also, these displays generally have to work in a wide variety of environments - directly in sunlight/heat/cold, vibrating/otherwise moving. Higher quality components cost a lot more money. Add more money for certifications required for medical or military deployments.
3) Spare parts. Again, the longer availability terms mean more costs for the support infrastructure - while for ordinary TVs the parts stock can be emptied out after 3-5 years, stock has to be kept around for way longer for commercial TVs, and that includes buying up spare parts when a supplier EOLs a part.
4) Features. Commercial TVs tend to have more selection of (rare) inputs, e.g. BNC or SDI (the latter to drive an array of screens around a spread-out location from a single signal source, you can't do that with HDMI).
5) Firmware. After three to four years no manufacturer except Apple gives a flying f..k about the firmware, which means security holes go unpatched. Commercial customers demand longer update cycles (and better validated ones), again that costs more money.
6) Vandalism and elements protection. This one is huge and ties into the quality part. While your home TV won't need to be protected much against anything, vandals will go and attack anything without mercy - with anything from graffiti over hammer blows to hydrofluoric acid. Add to that nature: bird crap, vomit, tree sap, pollen, drunkards stumbling into your digital signage... or humidity/harsh rain.
7) Loss of revenue from advertising, as you mentioned.
If that is the case, shouldn't the product then be labeled that part of the price is subsidized by advertisement so that in a free market customers can make informed decisions about what products they buy and under what conditions? Otherwise there is a huge risk that manufacturers that add such hidden drawbacks can unfairly out compete others who do not, we get a lemon market.
Another possible factor is that enterprises are willing (or even required) to spend more money to keep their data private and secure.
Content Management/Group Management
SuperSign Control Simple
Network Management Protocol (SNMP)
Wake-on-LAN
Crestron Connected® (Network Based Control)I went to the equivalent LG website for my country, and they don't even have a button for contacting them like in the link above.
So I did some searching for the model "LG UT640S" and I only found it sold on one website in my country, but listed as a smart TV (full number: "LG 43UT640S0ZA", parent ends in S0UA).
What gives? Do you need a company to be able to buy one of those? Maybe a sort of line of credit with LG? Buy in bulk? None of this makes sense honestly. I wanna buy a product that clearly exists in the world, but I can't even find someone, somewhere, that will sell it to me.
I say these TVs are just the right amount of smart. Maybe there are worse ones (I imagine, having once owned a Sony Playstation, that the software on a Sony TV is atrocious) but LG WebOS is brilliant.
Oh, and the checkboxes to disable some of the spying are buried on an industry-standard level of assholeiness, so that's good.
Decoding video is not any significant additional BOM cost (mostly just the network interface), and it is more convenient and nice for a significant fraction of users.... plus it allows the manufacturer access to additional revenue streams (e.g. getting some pennies for bundling Netflix).
As it turns out other people have different priorities than you do. The world not conforming to your personal preferences does not make it wrong.
Can't have you throwing a Heat (1995) DVD without it being recorded in a database, can we? Sure, your smartphone probably pics up the audio, but it may just report that you're listening to Moby.
Their life is not easier because of this, they don't watch what they want when they want because it takes minutes to get to a different source.
I know what I'm getting them for Christmas
If the intelligence is built into the TV then it cannot be updated or replaced -- so either there will again be multiple devices, or the TV will need to be replaced on a frequent basis.
A smart TV makes the problem you describe even worse
I think the new Chromecast is an admission from Google that the average person still wants a remote.
I personally prefer a phone but I also understand the preference of a remote. With a separate smart device these types of preferences can be accommodated over time, unlike with a one size fits all smart TV.
And in this context; in my 30s and I don't always know where my phone is; My parents, don't always have their phones accessible or know where they are without looking. Also, it's less tactile in the dark.
Wait until a decade from now, when all computers are like this, too.
https://www.nvidia.com/en-au/shield/
Being internet connected is one thing (which it looks good for), but having an active mic in the room is a whole other level of "no thanks" from me.
If you ever have an android phone in your home, it's exactly the same thing (except the phone actively listens by default).
Edit: Also, for fucks sake, context. The person I'm replying to is talking about getting his parents a SmartTV (way worse privacy-wise than Google), for the convenience factor.
This is not some tin foil hat idea. You can go on reddit and browse peoples personal spaces being broadcast for everyone to see.
Be pragmatic.
A TV with a good panel and a separate smart stick? :D
Really, that's the best choice. Always has been.
My neighbour called me because his Google apps (particularly, Youtube) stopped working on his smart TV. It's a cheap HiSense or something.
Still on warranty, but the store won't do anything as the hardware is fine, and they say the manufacturer is responsible for software updates. Which have stopped coming.
I'm pretty sure he didn't quite understand my "apps are Google property and they need to be updated every few months but this company stopped doing that" explanation, but anyway, he now has a dumb TV in the kitchen, and he specifically bought it so the wife could find recipes online, log in to Facebook and watch Youtube.
I told him to just get an Android computer stick, which will work just as well and last way longer. At the very least, it can be manually updated, unlike the built-in software.
Because that's what you should.
It takes 2 remotes to get the sound and hdmi to the right input. They are also confused about what apps it works with, or how to get to them (on the phone), and even though they have a Google Home, it only works with a few providers for voice control.
The TV automatically switches source to the game console when it's turned on and vice versa.
Couldn't be easier.
I haven't done any fancy hacking or special hw to get this working, just basic Samsung, Apple, a decent amp and a few minutes adjusting the settings of each.
Underpowered hardware running a non-optimized version of android...or worse.
If things weren’t done so badly, a unique interface would definitely be the way to go.
Thankfully, I don't know of any TV that requires internet access yet. AFAIK, they all can be used as dumb monitors. If you really want a dumb monitor, you can either buy a PC monitor or a commercial one, like those used in shops to display ads and stuff like that. Some are even as dumb as a monitor can be (like the one I am using right now), with only a single input, a single resolution, no OSD, and only an on-off switch and two buttons to control brightness (which is just a dimmer for the backlight).
But dumb monitor tend do be more expensive. First, they tend to be of higher quality, and second, "smart" features are often a profit for the manufacturer. For example, if your TV supports Netflix, Netflix most likely paid for it, and the amount is most likely more than what it cost the manufacturer to implement that feature. It results in a lower purchase price for the end user, the idea being that whatever partner will make up in subscriptions.
Apparently even 5G-NR has an equivalent of the wifi "unauthenticated deauth" intended for emergency quench of uncooperative devices.
The cellphone location data abuses revealed over the last three years have led to a remarkable increase in the number of GPS jammers out there. Gaussian-noise blurred, the good ones that can't be notch-filtered.
The technical battle is basically lost on IoT once they can embed modems.
What we really need, are proper laws to control/limit/stop all the tracking.
Most people with technical skills would not settle for being customer service representatives when they can make far more money by putting those skills to work in technical roles.
I once had Windows Update broken by my ISP DNS. It was just returning the wrong IP, maybe an old one, not sure.
Going to be a sad day for those advertisers when the DNS project gets killed by Google. Hopefully they are smart enough to set a alternate as well.
Fool me once, shame on you. Fool me 1500 times...
Per this site that tracks dead google projects, thus far they are at 220.
DNS is the latter. Google’s RSS reader was the former.
Very tragic, but things change. The nerd rage over Google Reader, etc is similar.
It’s pretty simple really. Google acts like a VC — place lots of bets on new projects in the hope that they’ll blow up and either a) start making adwords-scale profits or b) markedly increase adwords profits. Projects that don’t do either of those things are killed. The question is: Does 8.8.8.8 markedly increase adwords profit?
Track record: 8888 has been running for more than ten years.
Popularity: It appears to be incredibly widely used; e.g. a research paper from 2013 claimed it was serving 7% of all end user DNS queries, and Wikipedia claims that in 2018 it answered a trillion DNS requests per day (i.e. 10M qps).
Business value: It is true that there is no direct revenue here. But I'm pretty sure that the original reason for launching it was defensive. A lot of Google's networking projects have clearly been driven by trying to ensure that users can connect straight and reliable to Google's services with no interference from middleboxes, since every request lost to interference is also lost ad revenue.
Crappy ISP DNS servers that serve spam pages instead of NXDOMAIN are a pretty big vector here.
You calling it a tired joke doesn’t change these things.
I understand the point you're trying to make here - but long-lived products are still shut down by Google, fairly often. Here's a list of some Google products that have been / were around for 10 years or more before being killed (or are slated to be killed soon):
- Chrome Apps
- Cloud Print
- Fusion Tables
- Youtube Video Annotations
- Google Search Appliance (17 years old!!)
- Google Showtimes
- Google Code
- Picasa
- Orkut
- Postini
That's not even close to the full list of things that were more than 10 years old when Google shut them down. I left a bunch off for brevity's sake - but browsing https://killedbygoogle.com is a really eye-opening experience. They really have shut down a lot of stuff - and if you loosen the requirement to ">= 7 years" the list gets very, very long.
Again - I understand what you're trying to say. But it's just not simply a "zero effort joke". Google has killed a lot of things, and a lot of the things they killed were well used, long lived, and popular.
They'll keep Google DNS running as long as it provides business value to them, and that's it.
(Edit: I'm bad at list formatting, sorry)
> They'll keep Google DNS running as long as it provides business value to them, and that's it.
As in yes: I know it provides business value to them.
> Use your brain
Please be civil in your comments and refrain from insults. That’s not a charitable way to interact with others.
The point was that it's a multi-dimensional space, and the OP should actually consider the product rather than automatically go all "lol, Google product, bet it gets killed".
So if you think that "some old products were discontinued" is any kind of rebuttal, I clearly didn't make my point well enough. Of course that happens! The alternative is that any sufficiently old product would automatically become immortal, which would be a ludicrous idea.
8.8.8.8 clearly has a ton of users, which already differentiates it from basically everything on your list. It's also isn't something you could just put in a maintenance mode and forget about, unlike a lot of the things on your list, both due to the scale and due to the impact if it were to stop working. Something like "Google Showtimes" would not have been a big drain on resources for most of its lifespan... When there's a measurable cost to keeping a service running, the longevity does actually signal something about the business value.
Products with no users get killed by all companies. Products with hundreds of millions of users don't get killed with one exception: to migrate the users to a different product for the same task.
And that can't really happen with DNS! They can't replace the clients, nor force the clients to upgrade, and they can't change the protocol in a way that would force some kind of a migration. Even if they end up deciding that the service needs a full rewrite, the external interface will have to stay the same.
And once you think about the specifics, it actually becomes kind of an interesting discussion to have! What are the circumstances that could lead to this service being discontinued?
A complete migration from IPv4 to IPv6 might do it: part of the value of both this and 1.1.1.1 is that these are IP addresses that people can actually remember. Their IPv6 addresses do not have that property. Not holding my breath on that one though :-P And even if that migration ever finishes, it's plausible that operating systems start including a dropdown of well-known public DNS servers as one of the configuration options.
Could they replace DNS entirely? Come up with a "QuikDNS" that starts off as proprietary, is implemented in only Chrome and Android but never replaces DNS outside of their ecosystem? Or instead of a proprietary protocol just stop supporting classic DNS and only continue supporting DNS over HTTP? I don't see the former, there's just not enough wrong with the standard protocols for that to be worth it. I could definitely imagine the latter happening at very long timescales (like, not for at least 10 years). At the point where 99% of the traffic is DNS over HTTP, maybe the cost benefit ratio stops being there for classic DNS.
> and a lot of the things they killed were well used, long lived, and popular.
I don't think the examples you posted really match that description. Most of them weren't ever popular, let alone when they were discontinued. Maybe Picasa was?
but gog not using the harvested data seems somewhat unbelivable
1. Not join them to our networks 2. Stop buying 'Smart TV's' 3. Get panels and a smart box that you can control
I'm lucky enough to be able to direct ALL DNS through my router first. Nothing gets out without my say so. Not everyone has that capability, sadly, with home routers.
The solution provided by the OP is a solid one - another would be to purchase a decent router (such as a Mikrotik) and learn how to use it - much more powerful device for the same price, or sometimes lower, as a regular 'home' router.
Even DNS over HTTPS? Do you do packet inspection? Just blocking ports doesn't do much any more. I run an IDS/IPS and it blocks lots of DoH to Google. Apple devices are even worse.
1. Redirect all outbound DNS traffic to your own local DNS server (as described in the link in this post) 2. Return NXDOMAIN for well-known DoH domains [1] (as well as "use-application-dns.net" for well-behaving software like Firefox [2]) 3. Block traffic to well-known DoH providers by destination IP address [1]
[1] https://github.com/bambenek/block-doh [2] https://support.mozilla.org/en-US/kb/configuring-networks-di...
I mentioned Mikrotik previously - I use them myself.
Regulation should not be used to override clearly demonstrated consumer preferences or to force companies to produce products that few people want.
The first thing we need to do to have productive conversations about privacy with non-technical people is to stop pretending they are ignorant or unable to understand trade-offs. People know that their online activity is tracked. They know that their Alexa devices record their conversations. All of this has been on the news enough times that you'd need to be living in a cave to be unaware of it.
People know this, and they have chosen to purchase these devices anyway. Maybe it's not because they are stupid and need the state to protect them -- maybe they are capable of evaluating trade-offs and their choices ought not to be second-guessed by people who think they know better.
And then those same people complain about folks who won't vaccinate their kids, saying they're being selfish.
Without realizing they're doing exactly the same thing.
They are ignorant. They do not understand the trade-offs.
If they'd be presented a bill of what they're being overcharged through better targeting, ads, etc., the same way activity trackers show how many steps a user takes, things might change.
What I'd disagree is that people choose to purchase the device anyway, a non-tech-savy user will hardly get presented a non-smart device, wouldn't even know to search for this.
I think regulation should at least let you turn off features, e.g. it should be possible to use Airplay and turn off the app store the tv uses.
The article has convinced me to do exactly that and finally get a pfsense router to make the pihole more effective. I'll (try to) only allow each device to run the services I really want it to run. I doubt my partner, siblings, parents, etc. would be able to do that though, this needs a simple pfsense/pihole combo that runs well out of the box or regulation to protect consumers.
That's good though! If you are one of the people who wants a dumb TV, congratulations! You get to benefit from lower TV prices, subsidized by all the other people who are buying smart TVs for the smart features. Just don't connect your new TV to your network, don't try to use the smart features, and pretend it's a dumb TV. It works fine.
Roku? Where the CEO outright said that they aren’t in the hardware business and they are trying to monetize via ads?
Google? Need I say more
Amazon Fire devices? See above with Google
AppleTV? Sure I have a couple. They aren’t trying to monetize with advertising. But the HN crowd is anti-Apple.
Kodi running on a Pi or some other low power computer is probably HN-friendly, although the usability isn't even close to as good as the Apple TV.
You can also chromecast and airplay pretty smoothly as well.
As far as usability, look at all of the comments mentioning hacks solutions instead of just ordering a commercial product and plugging it in.
I went one step further with my parents. I just bought them a Roku TV and called it a day.
Once in a while I check the manufacturer's page, and if there's a firmware update, I factory reset my TV to remove any cached info about my usage, and then update the firmware via ethernet, and immediately remove it from the network.
A while ago I noticed that my old Insignia TV refused to use the pi-hole connected to my network, and it was constantly phoning home, that's when I decided that I'm never connecting a TV to the network. Thankfully I've been able to confirm that the Apple TV does not bypass my pi-hole, since it doesn't load anything when the pi-hole is down.
I know at some point I need to trust some entities with my data. I prefer choosing those entities to the best of my ability, rather than leaving that choice upto my TV manufacturer.
So the AppleTV has been a nice compromise, plus support for various media formats such as Dolby Vision, and HDMI-CEC are really nice to have.
https://www.forbes.com/sites/johnarcher/2018/02/14/lg-oled-t...
You're correct in general though, I'm not worried about security flaws on the TV.
I don't think that it's malevolent on their part. Lots of ISP DNS are crappy. Hardcoding a reasonably reliable one saves them a lot of frustration and unnecessary technical support.
Margins are already razor thin in hardware, so yeah anything that can be done to reduce your support costs is welcomed.
However, these IoT companies add these features mainly to benefit from selling the acquired data. The users are not asking for this. They're making it difficult for themselves.
I agree. I have support costs too. Which is why every company that sells a product with a hard coded DNS server configured but doesn't advertise said aspect prominently in all advertising, so I can know to avoid their intentionally defective product, should pay me $10000 for the time I wasted buying their product, discovering their product is secretly and intentionally broken, and then return their product.
This is done because the manufacturer’s and public DNS servers are more of a known quantity then you ISPs router and DNS servers. Using pihole is super rare and wouldn’t be worth the effort if it weren’t for the fact that it makes devices more reliable.
Saying that a device is not violating any standards as they "aren't required to accept DNS servers offered by DHCP" is like saying a device is not broken and not violating any standards because "they aren't required to accept IP addresses offered by DHCP." It's a silly to say devices are not required to accept the parameters sent by my DHCP server as such a statement is only correct in the most abstract sense that there is no law that requires a device to adhere to the relevant RFCs for DHCP. On the other hand there are laws, federally and in many states, that only allow you to connect to and use other people's network with their permission and only use their networks within the bounds that they allow.
I don't care about the device manufacturer's opinion of DNS server quality. I own the device and I own the network that the device is connected to and I pay for the uplink between that network and the rest of the internet. There is only one person who can correctly make an assessment as to the correct DNS server for my network and that is me. If a device manufacturer chooses to hard code a different DNS server they are wrong and it is broken and they should tell me so I don't waste my time buying their product and returning it.
Additionally they should advertise this behavior because it is a security vulnerability for my network for their shitty device to be sending my internal names to outside servers to resolve. The names of the devices on my network that I choose not to expose to the internet are no business of anyone else.
E: And I didn't even get into the mess that it would be to try and expose the DNS zones for the RFC 1918 address spaces that everyone is using.
The more convincing narrative is that setting custom DNS decreases ad revenue and cuts into growth.
The same thing that happened each time when DRM servers went offline. Time to buy a new TV :^)
"Sorry, your product is out of warranty, I can redirect you to sales"
On balance, I'd expect Google is be much better about maintaining their DNS uptime than most ISPs.
It's madness to me that people find this acceptable. These companies are profiting off the ignorance of people and misleading customers on what they're actually selling them.
As someone who has/might work for companies building things like that, it sounds like a nightmare. It's a ton of design, testing, translation, validation, etc work to build the UI for adjusting optional settings. And it has to be maintained and tested through all future versions, redesigns, refactorings, etc. It's gonna be a tough sell to do it right considering:
For every 1 techie who legitimately uses it to set it to his custom server and can handle debugging when it goes wrong, 50 people will accidentally set it to something random, or have some distant relative set up some weird hack and then disappear when it breaks, and then call the support line and rage at somebody when it doesn't work and they don't understand why, and rage some more when they can't get the instructions to reset it right.
Whatever feature somebody else is about to propose to fix that is yet another thing that will need design, validation, maintenance, etc forever. It's pretty understandable why product designers would rather build simple dumb UIs with no options that mostly work automatically.
Amazon sold two versions of their kindle, one with and one without ads, not an issue for me. As customer the pro/con relationship is clear. I get what I pay for.
These ads slow down my TV, waste electricity, waste my time more importantly. It's not my problem as a customer if other people mis-configure their TV and have to call support, that's a UX problem, I've never met anyone who has mis-configured their DNS on their phone. If you've updated your DNS on your TV before it's a very long process, using arrow keys to select characters, it's not something you accidentally do.
I paid for a TV and I didn't get what was advertised. The argument that they do it to protect dumb users is non-sense because the TVs that don't have this configurable in the settings are the ones mainly bundled with ads.
So I expect the device (at least the "smart" functionality) to be bricked as soon as Samsung takes that domain down for good. In fact Samsung already removed 80 % of the gimmicks and remote features the TV came with, some of them didn't even last two years.
The price for CEC-USB dongles is outrageous too.
https://blog.apnic.net/2020/08/04/characterizing-cname-cloak...
Which, honestly, will 100% happen, considering the sheer amount of weird "adsense click fraud rings" you can find on the shitty, awful part of the internet, like SEO forums.
It was kind of a revolution to set up these advertising middlemen. Site owners just sign up to show ads and set up their site to load an ad from the ad company's server. Advertisers buy their ad time from the middlemen too. Nobody has to maintain those high-overhead direct relationships. Huge boon for the little-guy sites on both sides. That's the good part. There's plenty of bad parts too, including monopolization of the market, abuse, poor behavior of anti-abuse mechanisms, etc. It's what we've got though, until somebody comes up with something better.
They don't trust each other; each has an incentive to defraud the other.
That's why they run separate servers. Auditability.
What made me give up on the search for alternative software is that there doesn't even seem to be a place in which any manufacturer's models are even listed, much less anything resembling a community.
Anyone who undertakes your proposal is going to have problems staying ahead of any jailbreaking mitigations when the companies motivation for security is maintaining relationships with content service providers.
Your “perfectly good computer” is in fact not yours (it has DRM so you are not the user, you are renting it), and it’s not perfectly good if it can’t run the software you want.
[1] This let’s you get away with just one remote including for powering on/off
https://github.com/tavinus/opkg-upgrade is one.
As it notes, the reasons you don't want updates on auto-pilot are those config differences, and limited space available on routers.
Not sure how relevant or up-to-date their support is, but at least there is _something_ :)
Far easier just to not connect the TV to the internet and use a third party solution like nVidia Shield instead. Fortunately pretty much no TVs will try to connect via open WiFi or 4G at the moment, though it is definitely coming.
0: https://www.amazon.com/Amazon-Sidewalk/b/?node=21328123011
There's just no strong motivation to try to root my TV. I don't like my smart TV but I don't need to, because the smart parts can be "replaced" by any number of external devices. My point is that I suspect many would-be TV hackers are in the same happy situation.
It is possible to buy 58 inch dumb TV, connect that to a machine you own.
I wouldn’t be surprised if manufacturers start selling TVs that need to be activated online before first use, but I don’t know of any that do that already.
I doubt that (at this stage) TVs have something similar builtin. When they come with Alexa/GHome/... it’s usually the software and not an actual Alexa device built in.
The real problem will be integrated cellular connectivity with no option to disable.
How the hell is this legal???
I'm waiting on some high quality "dumb" TV. I'll happily pay more for not having to worry about all this nonsense and my sense is that I'm not alone (though most people will happily continue to buy non-privacy respecting brands for a lower price).
Another option is to buy a monitor not a TV, but again because of market scale you'll pay a lot more for a monitor that large. They don't sell enough to consumers for volume savings to kick in, and they are aimed at commercial use so there is at least a little more "make it good rather than cheap" incentive than there is in other markets.
In my case, anything with a TV tuner requires an expensive license, so that's another motivating factor, but whenever I use someone else's "smart TV", I'm always relieved that I don't have to deal with glacial UIs and injected ads.
User friendliness does fall behind a bit, I'll give that.
And, while I don't use the speakers, the TV's S/PDIF output is nevertheless handy for routing the audio output of whichever of the four HDMI inputs is active to the single S/PDIF input on my audio interface.
Finally, the TV has an RS-232 port that allows control of essentially all of the basic "TV" functionality, which was handy for setting up keyboard shortcuts for input switching, power, and brightness control; IME, monitor controls for such things that don't involve diddling with buttons on the side of the device itself are few and far between.
"Bitrate Up to 48 Gbit/s, as of HDMI 2.1"
To answer your question: -Everybody does.
I work in a classified military space where the security of our equipment has been verified; our 80 inchers are all NEC and work wonderfully
When mounted in airports and the like, they are also mounted in environments where the lighting is usually such (i.e., much too bright) that nearly any screen (LCD or old CRT's) would generally appear "washed out". So the effect you see may not be the screens, but instead may be caused by the environments in which you generally see them operating.
There’s of course a price difference between you $300 cheapo consumer stuff, and a $1000-2000 pro display.
I used to have these pro displays at home with Chromecast, works fine.
Those cost way more than dumb displays did back before there were smart displays. Look at the 40-inch/43-inch models. They're like $800. I bought all my 40-inch 4k screens for under $300 in 2016.
The insane price gouging in these "professional displays" cannot be explained by advertising subsidies. We weren't paying those prices for equivalent-spec dumb TVs back when those were available for sale.
This is also becoming increasingly problematic.
Unfortunately they no longer make them. The 43-inch Sceptres have a HUGE black space between the pixels, which you will totally notice if you try to use them as desktop monitors.
Also, 40-inch 4k screens don't seem to exist anymore. The 43-inch and above have a MUCH larger inter-pixel gap which I can easily notice when using them as a monitor. 50-inch and above are too big for desktop monitor use.
I think the panel manufacturers realized they torpedoed their high-end monitor market with the 40-inch 4k screens which is why they had to nuke them and make the 43-inch displays so crappy.
Do I need to void warranty and dissect a new piece of consumer electronics to remove the spy organ? Is that really an acceptable situation?
That's bullshit because that could get into a HIGHLY illegal issue on the manufacturer as they could join into a foreign network tampering with comms. And IDK on the US, but the fines on Europe on that are really high.
Endgame is the FCC forces consumer-data-control on the industry because it's the only way they can get the 5G/GPS jammer problem back under control.
Then comes the other big thing. How am I supposed to spend so much when I can't see the thing before I buy it, and there's not much in the way of reviews?
I'm just hoping my next TV doesn't complain much when I don't connect it to the internet; not worried about it finding other networks to connect to, because of where I live.
I just spent 3 minutes googling for dumb tvs and found lots of them instantly. Why bother with commercial displays if you can buy cheap dumb TVs at Walmart? Here's a review for one [0].
And, of course, none or the fancy things like OLED or even local dimming/HDR.
Seems like an OK bet if you're looking for a basic TV though.
To be fair, Pi-Hole hardcodes "default" (suggested) DNS settings, too. While the user can change defaults, it is well-known that in most cases, the majority of users do not change them.
curl -s https://raw.githubusercontent.com/pi-hole/pi-hole/master/automated%20install/basic-install.sh |grep -C3 8\.8\.[48]\.[48]
IMO, the best DNS-based solution for controlling the HTTP requests that applications can successfully make, e.g., to ad servers/trackers, is not to point them (directly or indirectly) at third party DNS caches.Sending the user's DNS queries to an online ad services company (Google) is a interesting default for a project whose raison d'etre is the existence online ads. Perhaps if the online ads industry began to fade, so too would the need for Pi-Hole.
After decades of running own root and other authoritative servers on localhost, I would still do it even if online ads were not a problem. I like the speed, reliability and control.
The next step will be hard-coded DoH server IPs. Sly owners will NAT those to a transparent MiTM proxy.
Then device manufacturers will counter with certificate pinning for DoH. That will be "game over", and the device manufacturers win. (It'll be a double-win, actually. It will put a hard "expiration date" on the device's functionality when a link in the PKI chain expires.)
I believe the owner of a device has right to control the device's network traffic (and, more generally, control of the code running on the device). Business models that rely on taking away an owner's control of their rightfully-purchased general purpose computing devices are really rental models and should be handled as such.
I eschew these kinds of devices, use or create self-hosted solutions where I can, and just do without when I can't. It does make me a little sad that I can't get some of these cool "living in the future"-type devices, but I'd be sadder to have my home festooned with manufacturer-controlled surveillance and advertising delivery devices.
I wish there was a way to convince the average non-technical person of the merits of owner control. Given the enthusiastic responses in favor of allowing device manufacturers to mistreat owners I see from the Hacker News community, though, even convincing technical people is a lost cause. It feels like most people really want to be subjugated. It doesn't seem ratioinal.
I do recognize that the Hacker News community also includes some of the people who profit from subjugation of device owners. Their motivation seems rational (if not sociopathic).
If you're certificate pinning an IP address for use with your own software, you can just create a self-signed cert with expiration date set to 2999 or some commonly ridiculous date you don't expect your devices will live to.
In an alternate universe, "ability to control/mitm data going through your network" could have been argued to be a fundamental right such as "right to repair" and "right to be forgotten". Where is the EFF on this? Where is Stallman when you need him again? Why is Mozilla not fighting this instead of pushing DoH?! EU regulators? Anyone?
As long as people keep rewarding device manufacturers
who treat owners as tenants it will progress. I wish
people would just stop buying this garbage. They won't,
though-- they see the features but not the down-side.
I hope that folks who blindly espouse free markets above all else realize that this sort of thing is the inevitable consequence.Consumers nearly always shop with price as a primary concern, and almost never have the sort of detailed domain knowledge to understand pitfalls like the ones discussed here.
We certainly do not want the government to control too many things and should err on the side of freedom, but the result of too little consumer protection by the government means that situations like this are an absolutely guaranteed outcome.
Educated consumers are a good and necessary thing to have, but that falls far short of correcting the issue. It is impossible for a single person to have expert domain knowledge in every single product category. I've been a software developer for 20 years, so (relative to the general population, not HN) I am an "expert" of sorts in this field, but I am assuredly not also an expert in automobiles, food safety, home appliance safety, airline maintenance, medicine, or any of the other things upon which I might spend money.
1^4 exposes an endpoint on the regular IPs (1.1.1.1/dns-query) and dns.google is just pointing to the 2 IPs, so you could hardcode those as well. Not that you can redirect it:
> Sly owners will NAT those to a transparent MiTM proxy.
And do what about the pinned certificate/CA?
Is there such thing as 55" Monitor? The whole TV industry needs some new thinking and innovation. Right now it is race to the bottom and everyone is trying to get some extra revenues from Data gathering. There are also a huge oversupply from LCD panel maker.
You don't connect your TV but use Apple devices instead. Uhm... okay. You should see the IDS log I'm looking at here. Apple !== no telemetry. All you are doing is putting all your eggs in one basket.
Another option is to simply never give your smart TV any kind of network connection.
I can see running pihole instead of a pfSense+pfBlocker rig.
But if you've already got pfSesne at the edge, why not just polish it off with pfBlocker/DNSBL instead of erecting a separate pihole machine?
I could be doing something wrong, but I have no idea what.
I ended up getting a Fire stick and an Apple TV to go with it so I can access content. If I did it all again I wouldn’t even bother setting up the networking for the TV - it’s just one more vector for advertising - and just plan on having the other devices day one. They are updated much more frequently and get the streaming apps that nobody bothers to develop for the TV itself.
Downloading firmware updates for the TV takes hours. I’m pretty sure the server is under somebody’s desk and every LG tv in the world hits it at once so the throughput is bytes per second - they should use an S3 bucket or something instead.
But yeah, if they just used a CDN this wouldn't be an issue.
You can segregate your IoT devices from the rest of your stuff. You can even give a VLAN per device if you really want to, although it's probably not worth the effort.
I have 3 VLANs: one for my home network where my computers are, one for my security system, and one for the rest of my IoT devices. I don't even trust my Roomba on my home network!
I have a Unifi Dream Machine, but there are a few other consumer products that can achieve this kind of setup. If you have basic knowledge of how to use a computer, you can follow some YouTube tutorials about how to set up VLANs and firewall most of your devices from reaching your home computers.
I'm using OpenWRT and created a guest network which I configured to use certain DNS servers. All of my smart devices are connected to it. How can I check that those devices are actually using the DNS servers assigned at the router level?
Let's face it, the devs implementing these devices run a scrum process, features get stacked upon features and no one cares about, let alone understands the security of the whole tool stack. It is only a matter of time before we have a bot net of smart tvs and roombas. And network owners will be held responsible.
If you have an Echo/sidewalk-capable device already, you can opt-out of allowing other devices to use your sidewalk in the Ring or Amazon app https://support.ring.com/hc/en-us/articles/360032524592-Opti....
Forcing DNS requests to Pi Hole is the easiest option to defeat this.
[1] https://www.reddit.com/r/oneplus/comments/e0htyg/remove_goog...
Seriously. IPv4=8.8.8.8 means "this goes to the DNS server". The DNS server helps you find all the other IP addresses you need, which is why this one is special. One DNAT rule, one SNAT rule, and you're done.
IMO IP should have had this feature from day one.
Is there some reason why that's a terrible idea that I've overlooked?
pihole_addr='YOUR.IP.GOES.HERE'
for p in tcp udp; do
iptables -t nat -A prerouting_lan_rule -p "$p" ! --source "$pihole_addr" ! --destination "$pihole_addr" --dport 53 -j DNAT --to "$pihole_addr"
done
in http://openwrt.lan/cgi-bin/luci/admin/network/firewall/custo..., or whatever file it saves to, /etc/firewall/something I think.This solution would definitely not work for DNS Over HTTPS (DoH), which I’m guessing will soon become prevalent in many devices. It also seems like DNS Over TLS (DoT) isn’t going to get as much traction exactly because it’s easier to block.
As other comments have said, (for those who’re able to do it) not configuring any connection for the device sounds like a good start, but even that has caveats about the device connecting to nearby open networks. So the best thing to do instead is to connect it to a network but not allow any communications to the Internet.
DoT is upticking, albeit at a non-boosted rate. The number of servers supporting DoT has doubled in the US (as in from 3 to 6).
For best perforance, use a wired ethernet connection, and a bluetooth dongle for your non-Steam controllers and bluetooth headset.
Works flawlessly and it's a delight to have a full Linux distro on my TV.
Most smart TVs have built in web browsers, you can also try website like https://www.dnsleaktest.com/ to check your DNS.
I run my own custom openbsd router and use IP masquading to re-route any traffic on port 53 to my local dns server. My local server does caching, ad blocking, DoH resolution. Obviously with applications using their own DoH resolution this breaks as my local dns server gets bypassed.
Any application ignoring dns in a dhcp lease are bad net citizens unless the app gives the option to explicitly turn this on or off.
It’s also planed obsolescence, what happens when the hard coded dns servers get turned off? Everything just breaks.
Unfortunately packet filtering is considerably obscure and most of the people (including most of the programmers and other techies who don't specialize in network administration) are afraid of approaching it.
(If you have less money to spare, buy the TV and return it to the manufacturer for a refund, make sure you state the reason.)
Wanna use 8.8.8.8? Too bad!
I thought I was doing something wrong since the TV absolutely refused to accept the DNS settings I was inputting.
I would recommend pfsense. Once you choose your preferred OS, search online for some tutorials on stackoverflow.
Alternatively, you can always stick a firewall in between your home network and your netgear, and do your filtering on that.
Read it out loud a few times and imagine yourself in the VHS era.
It breaks app and system updates, but that's an okay price to pay :)
Has anyone got this working with a Unifi Security Gateway (USG3)?
[0]: https://dnsrpz.info/
https://github.com/berrypatch/berrypatch
(I guess I've reached the inevitable "build your own package manager" stage of one's hacking career..)
For now. Wait until Amazon Sidewalk takes off.
More specifically, https://labzilla.io/blog/force-dns-pihole#force-all-dns-quer...
...until they force all dns requests through DoH.
1. Do not setup your TV, do not except EULA. 2. Get other setup, PC, AppleTV and use TV as dumb screen.
Issue solved.
I had to firewall all dns requests as well...
I assume in the future they will put DNS over https and it will be harder to block - at which point a Linux media player and tv disconnected will make sense...
Doing this because of their crappy spying - sending frames of video to identify what you are playing.
“Your Smart TV is probably ignoring your PiHole” https://news.ycombinator.com/item?id=25313776
Maybe we count this one as an art performance?
<link rel="canonical" href="https://0.0.0.0:4000/blog/force-dns-pihole">
So some "Share" buttons may pick that up.
Unless you mean buy a separate box, put Kodi on it and attach that to the TV
It's not the correct title and it's harder for the uninformed user to understand. If you told me about hard-coded DNS settings I would say "Ok, what does that mean and why does it matter?". If you said "Smart TVs ignore piholes" (the original title) I would know exactly why that's important.
> I understand DNS a lot better than pihole
Unless the mods did a survey this doesn't justify the title change. It's just as likely that more people are familiar with pihole than DNS, and if the mods don't know (which they don't) then they should leave the title as the author wrote it.