Smart-TV blocklist for Pi-Hole
perflyst.github.io
perflyst.github.io
More annoying is the 15 second "home menu" that pops up on my OLED every time it is turned on. I almost always forget to manually dismiss it before I set the remote down and there's no option I can find to disable it.
I would pay a premium for a TV with no internet connection.
And also more expensive :) I wish I knew if that was because the crapware and ads on smart TVs are actually reducing the cost, or if it's just that smart TVs use crap hardware and software by comparison. Given how laggy they can be, that wouldn't surprise me.
At least in terms of the actual display parts. The smart TV probably has some processing capabilities that are incomparably better than what you'd get in a monitor. This is, of course, used to display ads. However, the ads are necessary to subsidize the cost of the powerful SOC... wait, why do we need the SOC again?
If you get quotes from chinese sellers on panelook, you'll find that monitor panels+drivers are cheaper than TVs with the same specs, even at 1pc pricing.
It's not clear whether they have HDCP, but... surely they must? That's table stakes for a computer monitor.
I bought a Samsung QLED TV recently, and it works fine without an internet connection. I did give it an ethernet connection to grab firmware updates, and it downloaded a bunch of ads and crap to clutter the home screen. Luckily, unplugging the ethernet cord and factory-resetting the device got rid of the garbage and kept the updated firmware.
FYI I was able to update the firmware via USB stick without much hassle.
GGP did mean HDCP 2.x (DRM to encrypt the signal between display and device) which is often not supported by commercial displays. Unless devices detect a compatible, DRM-protected display, devices will refuse to play UHD content made by the movie industry.
Even 12 year old NEC p-series (used at airports, usually) have hdcp.
All streaming services require HDCP 2.2 support throughout the device chain. Because commercial displays aren't intended to use on-device streaming services or be used in consumer environments they often lack HDCP 2.2 support. While they might support HCDP 1.4 or 2.0, that will only support FHD content either streaming or disc-based. It's fairly difficult to find specs on commercial displays about their HDCP support level.
Content obtained via torrent played, and still does, at 1080 perfectly well though, if you are looking for a workaround. I currently pipe stuff to the TV from my media array via Kodi on a Pi.
(I do actually pay for Prime, though mainly for the delivery options, and Netflix, but still consume their content "my" way more often than not)
I don’t know what your other child responses are talking about.
https://hdfury.com/product/linker-4k60-444-600mhz-scaler/
Even one of these cheap splitters should be able to provide an HDCP-workaround:
It's a ridiculous state of affairs that I have to jump through hoops just to get a TV to display a fucking video feed. I don't need or want the TV's software. I don't need or want a UI more complicated than the old analog TV genlocked character generator UI. I'll plug smart stuff into the TV if I want.
Edit: Added HDCP version
The "Smart TVs" are subsidized because they're robbing you and your mother of your privacy and security.
Don't get it twisted.
Painless experience and no ads.
Everything is so slow. Back when Freeview started being a thing in the UK, TVs then had a rapid TV Guide built in and everything felt instant. Now every screen change is a pause. I've got a PS5 so I'm much happier using that for apps.
It feels like feature phones were slow and laggy, we then got responsive smartphones. TVs were responsive, now they're slow and laggy.
Note that the router should not actually be connected to any other network.
DoH/DoT are just the camel's nose under the tent. Just wait (perhaps it's already happening) until TV manufacturers install 4g/5g modems in their devices.
At which point, there will be a market for TV-shaped faraday cages. Or not, as that will make actually watching the TV difficult/impossible.
This stuff really ticks me off. Grrr!
I hear this raised every now and then, but is that even feasible economically? Those embedded cell connections are a recurring cost, after all. I'm curious if the per-unit revenue from ads and tracking is large enough to justify the per-unit cost to send/receive that data over a cell connection.
Seems like UI nudges and dark patterns to push users into connecting their TVs to their home internet connection would be cheaper and more effective.
That's a great question. If it's not today, it likely will be soon.
I think it may be so already. These are niche cases, but the costs aren't so different than TVs:
I use a CPAP machine and the one I got six years ago had a cellular modem (as well as WiFi) without my involvement in any mobile account. Thankfully, I was able to disable that (and a big "Fuck you!" to Philips for being such rapacious scumbags).
I also got a Kindle as a gift in ~2004 or so and it had both WiFi and a cellular modem with no charges to me.
>Seems like UI nudges and dark patterns to push users into connecting their TVs to their home internet connection would be cheaper and more effective.
Cheaper? Definitely.
Effective? Most likely yes.
More effective than a cellular modem? Methinks not so much. A device connecting to a network over which you have no control would be much more effective, IMHO.
Aside from a small group of folks who will shoot, stab, defenestrate, bend, fold, spindle or mutilate such a device, most folks would likely just shrug and move on while being forced to watch ads.
And more's the pity.
If they make the TV into one of those monstrous Alexa Show (?) devices where you can make calls or do other things, they may be able to persuade some customers to get a connection for the TV. Even then it’s a stretch because most TVs are in one place for years and the places they’re in would have WiFi/broadband coverage in the same or a nearby room.
That doesn't seem to bother Amazon's Whispernet.
Amazon has been doing this for years[0]. Free cellular access for specific Kindle devices for specific purposes. They've sold many millions of those around the world.
Granted, Amazon was generating revenue from selling ebooks, which was the incentive for providing the service.
>There’s no way these TV manufacturing companies can buy one connection per TV (and accept the liabilities that come with such a connection) or get their customers to have one.
If they follow Amazon's lead, they'll enter into contracts with global networks (Amazon uses AT&T) for bulk rates on carrying their products' traffic.
That said, it's not at all clear to me what the break even point might be on a per-device basis for these TVs, but the first search result for "WiFI/LTE chipset price" yielded this link[1]:
ZTE 4G Module LTE Wireless Wifi Board with Sim
Card Slot Mini Router PCB for IOT Camera GPS
Sensor Data Transmission
1 - 499 Pieces $17.49
500 - 1999 Pieces $15.99
>=2000 Pieces $14.99
I'm guessing that Sony, LG, Samsung et. al can get much better prices for their specific needs than some random Alibaba listing. That, and they already have WiFi and wired ethernet, so adding the capability is easily within reach.Whether or not it would be profitable for the TV manufacturers is an open question.
I'm not saying that it will happen, just that it could.
And that would make me sad.
[0] https://smallbusiness.chron.com/amazon-whispernet-work-58992...
[1] https://www.alibaba.com/product-detail/4g-Lte-Zte4g-ZTE-4G-M...
Would manufacturers need to add cellular support if they could instead sign deals with other companies to auto-setup a wireless connection?
I realize Sidewalk is very low bandwidth, but I wonder if that's a problem for the telemetry data we're worried about.
Far more TVs are sold than those car navigation units ever did. I don't think money is an issue if they want a slow back channel. If they wanted to ship all ads over it, sure, but periodic phone-homes? Updates to DNS-bypassing lists of IP addresses? Unless they're prevented from selling it, they'll do it eventually.
Until this changes (and I don’t see it happening - if anything, the new generations seem even more happy with living in an advertising-saturated world), the people who resist will be a tiny minority not worth going after.
Roku devices hardcode 8.8.8.8 DNS in their software. So a Pi-Hole would be useless in a typical config. Evident by the constant hammering of dns.google in my firewall logs (dropped).
DNS filtering can only be effective if you intercept/drop all other outbound DNS traffic at the edge of your network.
Are they fussy about where responses come from? If not then you can redirect to your local filtering DNS service. If they do "protect" themselves that way then I'll add them to the list of devices that I'll never knowingly connect to my network.
No premium required. Just set your TV's with a static IP address and block outbound access to that address at your firewall.
I also blackhole the DNS entries of specific hosts that the TV attempts to contact. Blocking the IP address is sufficient, but I choose to nuke it from orbit. It's the only way to be sure. ;)
If you're assuming the TV is malicious, why trust it to honor that static IP setting? Doesn't even have to be malicious - a bug or carelessness could mean that it temporarily falls back to DHCP for some time in the boot process.
A separate VLAN (or wireless network) with the entire thing isolated and not being able to talk to anything is the way to go, but there just aren't many reasons to connect it to a network to begin with so save your time and just don't.
I guess you missed this part, eh?
I also blackhole the DNS entries of specific hosts
that the TV attempts to contact. Blocking the IP
address is sufficient, but I choose to nuke it from
orbit. It's the only way to be sure. ;)Why pay a premium when this is something that is extremely easy to achieve? Simply don't connect your TV to the internet. Criteria met. If you want to go further, you can also easily remove the WiFi antenna and ethernet ports.
There is a solution for which time is running out but is currently still possible. You can find someone selling a used, perfectly good television made in the era right before every single TV was a "smart" TV.
I am just waiting for the first "smart" computer monitor
* https://en.wikipedia.org/wiki/HDMI#HDMI_Ethernet_and_Audio_R...
There's no reason to believe this won't be a configurable option on the box itself, but this is a moot point because I have yet to see anything in the wild actually supporting Ethernet over HDMI.
I ended up with a Costco 85" LG and unplugged the WiFi card before turning it on, and so far it's worked very well for me.
I wish I could have voted with my wallet on this.
Unfortunately the LG soundbars - which integrate well with the TV - use a wifi based wireless subwoofer. the soundbar becomes a wifi access point.
There don't appear to be any wired soundbars. I guess a component speaker system + receiver is the solution, which is probably much better sound anyway.
https://sfconservancy.org/copyleft-compliance/vizio.html https://wiki.debian.org/PrivacyIssues
https://sfconservancy.org/copyleft-compliance/principles.htm...
Its pretty clear that Vizio violated the GPL, the question to be answered by the case is who gets to enforce the GPL.
If Conservancy win this case, then they get the precedent set that any recipient of GPLed binaries gets to sue for GPL compliance. That precedent applies to any person or company that distributes Linux or other copyleft code on hardware or elsewhere. That means any person who buys Linux hardware can sue if it doesn't come with source code. Potentially that means many more possibilities of GPL compliance suits, maybe even class action ones. The threat of that and the actual suits in turn will hopefully lead to much higher amounts of GPL compliance.
If Conservancy lose this case, then the copyright holders still get to sue for GPL compliance and I assume Conservancy will switch to pursuing Vizio in this way.
I think the LG OLEDs are the best available option, but they’re not perfect either.
NextDNS is also great for something a little easier to manage than PiHole (plus also easy to use outside of your home network and on mobile).
Nice one. Added to https://github.com/globalcitizen/taoup
> Nearly 70% of smart TVs and 46% of game consoles were found to contain hardcoded DNS settings - allowing them to simply ignore your local network’s DNS server entirely.
Though in the case of a smart TV, you would want to block everything except for whichever streaming services you're subscribed to.
edit: method for this on pfSense: https://docs.netgate.com/pfsense/en/latest/recipes/dns-redir...
DNS over HTTP has got to be the most ill thought out "privacy" feature that has done more to HARM privacy then it could ever help
Whose privacy? DoH helps to protect billions in revenue for the ad network that funds Chrome, Firefox, Safari and web standards.
A better web will need a different revenue model.
In the meantime, here's a maintained guide to blocking DoH with pfsense, https://github.com/jpgpi250/piholemanual/blob/master/doc/Blo...
Says who? I think your data is very old considering that ECH replaced ESNI 2 years ago. IIRC it has ~50% adoption, same as TLS 1.3. Just about every company that cares about security supported ECH for years.
Moreover, someone has to move first. If DoH wasn’t widely deployed you’d be complaining that ECH is useless because DNS is unencrypted.
People really are gulible aren't they...
DoH is a not or a privacy feature. It simply changes who is collecting your data and makes it harder for responsibile network operators to protect their users under the guise that the big tech companies are really protecting the users from the network operators and "big bad ISPs".
Ironic given the billions big tech is making from that data.
In the case of cloudflare, it is going to be interesting how they continue to justify the free public services to institutional investors now that they are public. I have a feeling there is going to be some strong pressure to either cease the free services, or find away to monetize them which likely will involve some kind of usage of that data maybe not selling per say, but some other kind of targeting or something to add to the profitability of the company.
I am no more comfortable with cloudflare having my data than I am with google or verizion, I have never used any of their DNS services
> I am no more comfortable with cloudflare having my data than I am with google or verizion, I have never used any of their DNS services
It's not either/or. If you use Cloudflare or Google DNS and it isn't encrypted then Verizon has it too. With DoH they don't.
Web browsers are subsidized (free) by search (ad) revenue.
Authors' Addresses
Paul Hoffman
ICANN
Email: paul.hoffman@icann.org
Patrick McManus
Mozilla
Email: mcmanus@ducksong.com
* https://datatracker.ietf.org/doc/html/rfc8484DoH is the problem here, as it hides things from network operators making it harder to block ads, spam, and other items at the network level under the guise of privacy, when in reality DoH's actual goal is to further centralize the internet into approved gate keepers like CloudFlare and Google.
https://codeberg.org/unixsheikh/dohblockbuster https://openbsdrouterguide.net/#blocking-doh
https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/m...
(Though it is included as a preset, already, in AdGuard Home.)
In terms of configuring firewalls/etc, it really depends on your equipment, however in most cases there's already a catch-all rule to allow any established & related traffic so you only need to add a rule to allow the initial connection establishment from LAN->TV.
> since you seem to imply it's different than searching about VLANs since it's wireless.
When it comes to VLANs, the idea is that the Ethernet port of the TV should either be connected to a managed switch that will tag any incoming traffic on that port with a VLAN tag before sending it upstream to your router (so it can tell what it is, since at that point it'll be arriving via a port that also has trusted LAN traffic), or connect it directly to the router and have that router's port not be part of the LAN bridge.
You don't have VLANs in wireless, instead you just create a new network - however the access point itself will need to either tag all traffic from said network with a VLAN tag (so again your upstream router can differentiate between that and trusted LAN traffic arriving over the same port), or if the AP is incapable of VLAN management then dedicate it to the TV network and connect it to a managed switch or dedicated port on the router as described above.
Meanwhile, do the VLANs allow the "enumerate devices" style multicast to come down from the regular LAN and be responded to?
HTH.
usage-us-fy2014.myhomescreen.tv
...
usage-us-fy2018.myhomescreen.tv
usage-us-fy2019.myhomescreen.tv
usage-us-fy2020.myhomescreen.tv
usage.myhomescreen.tv $ dig @8.8.8.8 +short usage-us-fy20{18,19,20,21,22}.myhomescreen.tv
199.239.141.74
213.198.25.172
213.198.25.174
213.198.25.177
213.198.25.177
Probably a good opportunity for an update to the blocklist.Edit: Opened a PR: https://github.com/Perflyst/PiHoleBlocklist/pull/126
Money solves a lot of problems, and people at tiny companies seem more likely to actually care.
Maybe they shouldn’t? Either block European traffic or do whatever you want and figure it out later when you’re big enough to be on somebody’s radar.
I just have to check manually once in a while and disable while I update the firmware. Of course firmware in most cases can also be updated via USB.
If your router is OPNsense, you can manually configure a DNS blocklist. https://docs.opnsense.org/manual/unbound.html#blocklists Don't forget to enable a blocklist refresh entry in cron.
Our old LG TV stopped working last week, and we're getting a replacement Sony on Monday. I'm hoping the worst features are relatively easy to block with OpenWRT while leaving the rest of the built-in features working correctly.
(I am not affiliated with Sony, beyond working for their broadcast R&D in the UK over 20 years ago)
The new system uses a weird management style -- a combination of on router settings (https://10.0.0.1 whatever admin console) and an ISP portal. I can't set port forwarding unless I go to the ISP portal. I suppose it's to support the mobile app they are pushing. The lack of DNS customization is a pain though.
A) $50/month with your own equipment and a data cap
B) $80/month for the same as (A), but unlimited data
C) $60/month for the same as (B), but higher bandwidth and using the ISP's equipment
What horrible things are they doing with that router that they would effectively pay you $20/month to use it for
- they get some data on how many (and what) LAN devices you have
- they face fewer support calls from people using DOCSIS modems with one of the buggy intel chipsets, and from people with a random router/modem combination that their support people aren't trained to debug
- they can expand their wifi hotspot network (the xfinity wifi hotspot is enabled by default, but the user can turn it off)
Your own router will need to use a different private address range (e.g. 192.168.1.x or 172.16.0.x) because then you'll still be able to connect to the xFi admin interface on 10.0.0.1 (e.g. if you decide to turn off bridge mode).
I kinda like some of the features they offer in the mobile app. Would be a shame to lose it.
I actually switched away from Shaw due to my dissatisfaction with their router/modems. Their modems are all have obnoxiously high power draws (active cooling required?!), can't have wifi entirely disabled even if you use your own access point, and all use the trashy[1] Intel PUMA chipsets. Switched to TekSavvy using Shaw last-mile infrastructure so I can use my own modem and chipset. (And support TekSavvy's lobbying efforts.) Losing access to the Shaw hot spots was a bit of a pain, but for me, it was worth it.
I’ve got no real skin in your pick of router though, the Shaw one is fine if you’re okay with its limitations.
These are commented out, but did someone really think the app would still work after blocking these? I get blocking ads, but I don't understand the mindset of someone who wants "smart" features but still wants to block everything.
2. The comments also serve as a "no really, don't block these" reminder to enthusiastic contributors.
Based on current comments if I were to buy today it'd be a Spectre. The more consumers who refuse to buy a TV with mandatory advertising, the sooner it will stop being profitable.
So is it very difficult to buy a non-smart TV or do they just cost more?
It's difficult.
- 2x 10-20sec at the beginning of every video (even e.g. 30sec clips)
- Then, usually 2mins in the Yt themselves do an ad
- After that, at around 3mins, another 2x 10-20sec ad block.
I've started to work actively against it now since my viewing experience is suffering. I have a pihole but it doesn't do much.
When I bought my first smart TV (mainly due to lack of dumb screens), immediately grabbed a Pi-Hole and started blocking everything I could find.
Also, one of the only occurrences where I’m skeptical even updating the tv software.
(edited to add) I feel like the real problem will be when they start adding wireless connectivity that you can't disable. I can keep my LG off the network today by refusing to configure networking for it. I can't do that if it doesn't use/require my network...
TV still works (minus the streaming services). If you try to open the network settings the screen just shows a loading icon indefinitely.
This gets raised all the time but I just don't see it being necessary - the vast majority is happy to voluntarily provide it with an internet connection. The ones like us who fight it is a very small minority not worth spending on including cellular modems (& the associated data plan) in every TV.
I think this is way further out than people may realize. I've done pentesting in a lot of different office networks and 53/UDP is open for all, but not 443/TCP unless you're a known device.
How do you block DoH?
Hate to say it, but invisible TLS-intercepting proxies are more widely used today than they were in the 90s.
Technically, the provider could use something else, but are they so worried about ad blocking that they’ll run BGP anycast themselves?
On 443 blocking: Doesn't that defeat the purpose of having a "smart" streaming tv. If you are willing to blanket deny 443 you might as well just block the whole address and turn it into a dumb tv.
And on that note. I have set up unsecured wifi access points before and seen the neighborhood samsung tvs eagerly use it to send their nefarious spyware payload.
im telling you these non-standard unrootable bricks companies keep creating needs to stop. need to balance security and right to own your own device!! let alone enviromental considerations.
EDIT: did some research after asking like a responsible requester of such information and found https://github.com/britannic/blacklist . Looks promising :) I’d be interested if you settled on another solution.
The DNSMasq blacklist package has a command line to add other blocklists (but you come up with your own name for this list - couldn’t get this in my head when I was first setting it up). Limitations over Pihole is that there no regex and no pretty UI.
I’ve also set up firewall rules to redirect DNS traffic, but not sure how effective this is with DoH becoming mainstream. The guides I’ve found online all use the UI, but would love to be able to find a CLI guide.
Here is the guide I used: https://www.derekseaman.com/2019/10/redirect-hard-coded-dns-...
Also, should have a shoutout for the GRC DNS benchmark to find the fastest DNS relative to me: https://www.grc.com/dns/benchmark.htm
Are dumb TVs still a thing?
Dumb TVs are difficult to come by, what you now need is professional displays.
They come in different ranges and the prices & features vary a lot. Digital signage ones which might be a poor fit for a TV as they're very expensive, have different reliability requirements (24/7 operation) and may lack some features such as 4K, HDR or HDCP which are desirable if you want to use it as a TV. The ones designed/marketed for meeting room use would be my suggestion - are usually based on the same hardware as the consumer version which means you get all the features you'd expect from a consumer-grade TV (the tuner is the only part missing) and cost-wise are reasonable compared to digital signage displays.
I've had good luck with Sony's professional display range: https://pro.sony/en_GB/products/pro-displays - they are reasonably priced (in my case the markup was around 1/3 more than an equivalent consumer-grade version) and give you what seems like a consumer-grade TV with all the normal TV features but a cleaned-up firmware (bare Android TV with no BS, though the Play Store is there if you want, and you can install APKs such as Kodi directly).
this garbage with "smart" electronics is getting on my nerves
[1]: https://pi-hole.net
But you most likely do know: so what would it actually take to make you care about what they are doing over your wifi?
Transmit every remote control button push? Send hashes of audio keywords recorded from you talking and use that to recommend shows/products? Raw lidar data? Raw audio/video recording of you/your house?
Is there potentially a line they could cross, or is data just data, and therefore equally fair game?