3 ms·
I have connected it to my network and then blocked it off the internet via Pi-hole. That way, I hope, it'll not try to scan for other open networks.
by krtkush 27d ago
I have connected it to my network and then blocked it off the internet via Pi-hole. That way, I hope, it'll not try to scan for other open networks.
- orev 27d agoIt’s still scanning (or at least listening to) all the other devices on your local network, like your phones, PCs, etc. It collects an inventory and if it ever happens to get Internet access, uploads that data.
- phraun 27d agoThat's why you put IoT crap into an isolated vlan with its own ssid, enforce device isolation for that ssid across all WAPs, and enforce isolation on the vlan level with your switches to cover any hardwired devices.
- dogcow 27d agoThat's not really sufficient. It could still phone home if it falls back to IP addresses. You should be blocking it at the firewall level, not just with DNS. But me personally, I wouldn't ever connect any of these devices to my network.
- krtkush 27d agoThe only reason it is on my network is that I need it for home automation (via home bridge). I'll have to see what else I can do.
- chorizo 27d agoFirewall rule that prevents the tv from accessing the internet (by mac address if using dhcp, or set a static ip for the tv). Or stick it in separate quarantined IoT subnet with your devices.
- Nas808 27d agoSome of these devices also now use DoH to bypass any DNS-level filtering.