Remix.run Logo
amazingman 4 hours ago

Hope you don't have any open WiFi networks nearby. IMO it's better to put it on one of your networks and isolate it from the internet and other devices.

tyre 4 hours ago | parent | next [-]

Yes. I bought a Samsung TV and there isn’t a way to set up Art Mode without the internet. So first you have to get a raspberry pi, install pi hole, then switch your router’s DNS.

What a wild experience 2026 is. But I do feel like a wizard.

walrus01 3 hours ago | parent | next [-]

You don't need an actual physical raspberry pi to temporarily run pihole on your LAN, you can, for instance, install a barebones debian VM inside any common hypervisor on your laptop like virtualbox or qemu, then install pihole on that basic debian x86-64 system.

3 hours ago | parent [-]
[deleted]
entropie 3 hours ago | parent | prev | next [-]

They might hardcode DNS. It's not certain that this will work.

slau 3 hours ago | parent | next [-]

This is why I’m a bit conflicted about DoH and ODoH. Firefox and Chrome have defaulted to DoH for years if I’m not mistaken (although I’m in Europe so I believe my FF still uses regular DNS instead of DoH by default).

This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.

TeMPOraL 31 minutes ago | parent | next [-]

That's why I'm not a fan of DoH or certificate pinning. Those are tools of control.

tkel 3 hours ago | parent | prev [-]

I have my router set with iptables rules to block/redirect all port 53 and you can also add known DoH to a blocklist to try and force LAN devices to use your router DNS.

lodovic an hour ago | parent [-]

I have a separate lan for untrusted devices, I only use whitelisting. No public DNS for these devices.

Jnr 28 minutes ago | parent | prev | next [-]

I block known DoH servers on my lan and forward all dns requests to my dns server.

CyberDildonics 3 hours ago | parent | prev [-]

You can intercept normal DNS with iptables rules.

The best way to deal with a TV you don't trust is what no one wants to hear.

Open up the back and disconnect the wifi antenna. It is easy to open them up and everything is pretty simple and obvious once you do.

drnick1 an hour ago | parent [-]

> Open up the back and disconnect the wifi antenna.

Upvoted. This is precisely the kind of thing I expect to read on HN.

drnick1 an hour ago | parent | prev [-]

> So first you have to get a raspberry pi, install pi hole, then switch your router’s DNS.

This does not provide any meaningful protection against data exfiltration. The TV is very possibly using public DNS or outright phoning home through stable IPs.

MrDrMcCoy 4 hours ago | parent | prev | next [-]

If it connects to another network, it's somebody else's problem. Unless of course, it has a built in webcam or microphone.

stvltvs 3 hours ago | parent [-]

It does, at least for any media played through the device. Read up on automatic content recognition.

https://www.howtogeek.com/its-not-just-streaming-content-you...

RiverCrochet 4 hours ago | parent | prev | next [-]

I haven't seen any open WiFi networks around me in years. I don't think it's a thing anymore; it's definitely not something a TV company can rely on.

baby_souffle 3 hours ago | parent [-]

They're not unheard of in cities. Hotels and shopping malls have them. Some residential ISPs will also broadcast a public access point using a slice of each customer's bandwidth allocation...

drnick1 an hour ago | parent | next [-]

Another reason not to use ISP hardware. That's on top of a well-known backdoor (https://en.wikipedia.org/wiki/TR-069).

dhosek 3 hours ago | parent | prev | next [-]

When I had Comcast internet, I could get on those, but it required a network profile to actually connect to the internet. That said, I wouldn’t put it past TV makers and Comcast to collude on using this to allow backdoor network exfiltration.

prmoustache an hour ago | parent | prev [-]

They all have captive portal for regulatory reasons though.

Symbiote 11 minutes ago | parent [-]

Depends on the country.

The cafe I live above in Denmark just has an open network.

Hamuko 3 hours ago | parent | prev [-]

I have an open guest network with a captive portal, and not once have I seen my LG TV try to connect to it.