4 ms·
I asked Claude to scan my network and check if LG tv is sending data, it said yes. Some domains were blocked by my router some were not, now Claude blocked all
by sumedh 20d ago
I asked Claude to scan my network and check if LG tv is sending data, it said yes. Some domains were blocked by my router some were not, now Claude blocked all lg related tracking/ad domains on my router.
Domains which are blocked now.
prov-lg.alphonso.tv au.info.lgsmartad.com kic.cdpbeacon.lgtvcommon.com au.nextlgsdp.com kic.tv.wiselg.com kic.wiseconfig.lgtvcommon.com kic.homeprv.lgtvcommon.com kic.recommend.lgtvcommon.com au.elastic.lgwebostv.com
- deleted 20d ago[deleted]
- ButlerianJihad 20d agoI like how you've piecemeal blocked the same subdomain 4 times. Will you do the same for the other 4-component subdomains? In fact, I'm curious what it means to "block a domain at a router". Really? Did you give Claude the credentials to your managed switch so it could set up a mirror port? Did Claude enable promiscuous mode on your Ethernet interface? Did Claude get a master-mode WiFi AP to intercept all the frames, or did it use SDR? Tell us more about how Claude scanned your network. I am HN-curious about this!
- sumedh 20d agoI gave claude ssh access to my router, the router has a block list where you can block domains. It monitored the network traffic from the router.
- vrganj 20d agoSo in trying to get one big corp from spying on you, you gave another the keys to the castle? I really don't understand how people give models run on somebody else's server these wide-reaching permissions. Do you really trust Anthropic that much? The government that's hosting Anthropic?
- ranguna 20d ago"Giving the keys" doesn't necessarily mean outright cat the private key to Claude. You setup the key, configure SSH config to use it and you can just SSH to the machine without ever seeing the keys. Stop fear mongering unnecessarily.
- vrganj 20d agoI wasn't talking about the literal key files, I was talking about the metaphorical keys to the kingdom. No matter how you set it up, you're giving a cloud service the ability to SSH into your private network. Surely you must see the glaring security risk this creates?
- sumedh 19d agoThat is a fair point I should have done with a local LLM instead of Claude. But not exactly sure what the main issue, how can claude even access the router from the internet. Its not accessible.
- dumberquestions 19d agoHow is that any different from calling Claude from any device in your local network? Or is 2 devices that much worse than 1?
- kadoban 19d agoYou know you can monitor/reject things it attempts to do, right? For anything important I have it write scripts for what it wants to do, then I can review them for anything troubling.
- ranguna 19d ago> Surely you must see the glaring security risk this creates? Enlighten me.
- vrganj 19d agoI would recommend reading up on the basics here: https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/remote-code-execution/ https://www.crowdstrike.com/en-us/cybersecurity-101/cyberatt... https://www.varonis.com/blog/what-is-c2 https://www.varonis.com/blog/what-is-c2
- deleted 19d ago[deleted]
- petre 19d ago> I gave claude ssh access to my router Jesus.
- tmcz26 20d agoI have AdGuard running in my home lab and pointed the router to the AdGuard DNS resolver. I have some general block lists and a special Smart TV block list. I asked DeepSeek to do the same scan, but given everything goes through AdGuard it’s much simpler to sift through it’s logs. This is what I got: * br.rdx2.lgtvsdp.com, br.lgtvsdp.com — 1,200 hits: LG’s ad/content-delivery platform (SDP) * br.info.lgsmartad.com — 64 hits: LG Smart AD advertising network * aic.cdpsvc.lgtvcommon.com — 141 hits: LG customer-data platform (CDP) * aic.cdpbeacon.lgtvcommon.com — 34 hits: CDP data-collection beacon * aic*.lgtviot.com, *.lgthinq.com — ~410 hits: LG ThinQ / IoT cloud * lgtvonline.lge.com — 350 hits: LG online services / telemetry * br.lgeapi.com, ngfts.lge.com, aic-gfts.lge.com, snu.lge.com — ~210 hits: LG APIs + telemetry Of those, these were already blocked: * rdx2.lgtvsdp.com (600/600) — LG ad platform * cdpsvc.lgtvcommon.com (~370) — LG customer-data platform & beacons * info.lgsmartad.com (78/78) — LG Smart AD * ibs.lgappstv.com (86/86) — LG app store * aic-ngfts.lge.com (36/36) General list also catches: Netflix logs (6k), Amazon telemetry.insights.video.a2z.com (700), Datadog (600), Conviva (410), Google DoubleClick (98) Though some domains still are going through, which are now blocked :)
- justinclift 19d agoDNS over HTTPS stuff wouldn't be caught by this would it?
- nearlyepic 19d agoYknow, admitting you have no idea what you’re talking about and coming up with a solution that doesn’t actually work used to be free.
- sumedh 19d agoWhat?
- frumiousirc 19d agoApparently, nearlyepic is trying to deliver two veiled insults and a critique of judgement or perhaps of the current state of broader affairs. I'll attempt to translate: - "no idea what you’re talking" = "you have outsourced expertise to an LLM" - "solution that doesn’t actually work" = "piecemeal blocking leaves many problems still active" - "used to be free" = "you / others in general now pay LLM services for the outsourcing leading to poor solutions while in the past poor solutions came for free"
- nearlyepic 18d agoThanks, I’ll work on accommodating the reading-comprehension-impaired in the future.