4 ms·
I use the PCWRT router, and it allows me to block the spying by blacklisting the relevant domains. https://www.pcwrt.com/2018/08/how-to-use-your-router-to-bloc
by myrakle 7y ago
I use the PCWRT router, and it allows me to block the spying by blacklisting the relevant domains.
https://www.pcwrt.com/2018/08/how-to-use-your-router-to-block-smart-tv-snooping/ https://www.pcwrt.com/2018/08/how-to-use-your-router-to-bloc...
- butz 7y agoAny way to build something like this myself, e.g. using Raspberry Pi or DD-WRT supported router?
- netsharc 7y agoGoogle Pi Hole, it's mostly for ads and trackers, but someone probably has a list of "call home" domains, or you can add your own domains/hostnames that you want blocked
- ownagefool 7y agoI believe the blocker just uses a dns server that returns a local IP address for bad domains that serve up a single pixel transparent in place of the ad, so there's a solution on pretty much every platform. Pi-Hole has a nice GUI, but if you already have openwrt, dd-wrt or pfsense, you can likely just install packages.
- jquinby 7y agoThere is indeed such a list: https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/SmartTV.txt https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/m...
- myrakle 7y agoDD-WRT would probably let you block domains. Pi-hole might be useful too. To be effective, you need your black or white listing to be device specific, so that you can block your smart TV in whatever way you want to without affecting other devices.
- garrettdimon 7y agoWe have three TCL Roku TV’s, and while they’re all blocked now, they were responsible for about 98% of the requests on our network according to Pi Hole. Now they’re blocked at the router level as well because it’s hard to trust them at all. Pi Hole doesn’t block them by default, but the endless requests to Roku domains are easy to blacklist.
- ImprovedSilence 7y agoDoes a pi-hole or the like not already take care of this?
- Mirioron 7y agoAt some point I wonder if we might not just start whitelisting domains instead. I think that it could be possible to design a UX that wouldn't be much of a hindrance to using your computer and phone on the same network. Eg any websites you deliberately visit get added to the whitelist, same with the other services you choose to use. The amount of mostly unintentional (by the user) data transfers is out of hand.
- Silhouette 7y agoAt some point, a combination of manual/explicit reputation tagging and a web-of-trust system might become a plausible defence against a lot of these user-hostile connections. If your corporate site, where you advertise your new high-end TVs and laptops, starts triggering warnings in all your visitors' browsers that it might be associated with malware and falling off all the SERPs for similar reasons, you're going to stop loading it with junk pretty quickly (and its trust score will improve pretty quickly as a direct result). Likewise, if your smart device tries to phone home and home has acquired negative rep, maybe that connection gets blocked automatically at the firewall. We'd need a system that was guided by interested/aware participants who are unlikely to be successfully gamed and that mostly "just worked" for average users, but we've managed to build those in other contexts before so it doesn't seem completely out of the question.
- myrakle 7y agoActually, white listing is a better idea. You can white list with the PCWRT router too.
- egdod 7y agoAnd then everybody starts collecting data via AWS or whatever.
- Mirioron 7y agoEven then, can't you tailor the whitelisting in a way where it only whitelists specific services on AWS? You could even make it timed so that other IOT devices can't exploit it.
- ananonymoususer 7y agoAnother good alternative (for those of us who home-brewed their own router) is pfBlockerNG, which is an optional module for pfSense. It can do everything that Pi-hole can do, and more.
- zigzaggy 7y agoCan I flash my own router with pcWRT or do I have to purchase one on Amazon? Is this similar to DDWRT? Or a fork of some open source project?
- move-on-by 7y agoHow long till the embedded devices us DNS over HTTPS to bypass this? The consumer is under attack
- egdod 7y agoI assume not long. And there’s no good way to stop that.
- Silhouette 7y agoAnd there’s no good way to stop that. As long as they rely on your own network for their external connectivity, you can always firewall them (at the expense of any connected features you do want to use, perhaps, but then I suspect most of us would agree that 99% of those are junk in most smart TVs anyway and be OK with that limitation). The problem comes when they can form their own connections, but in that case they're not under your control anyway, DoH or not.
- egdod 7y agoBut that breaks the streaming functionality.
- prepend 7y agoJust stream using a separate box connected over HDMI.
- move-on-by 7y agoAnd then that device will do the same tracking/spying as the TV
- Silhouette 7y agoThey might try, but any such device will likely be much more interchangeable than the TV itself, with more competition. One significant problem with the TV industry at the moment is that competition has failed and essentially they're all at it.