Naughty IoT ("Internet of Things") devices
#1
Original Poster
FlyerTalk Evangelist



Join Date: Nov 2002
Location: ORD
Posts: 14,773
Naughty IoT ("Internet of Things") devices
I recently discovered that my Samsung TV ignores the DNS server specified by my DHCP server and just uses 8.8.8.8. No wonder I still see ads on it. I had to set a NAT rule to override outbound port 53 and redirect it back to NextDNS.
It seems the only other devices on my network that do so are a couple of work-managed laptops.
It seems the only other devices on my network that do so are a couple of work-managed laptops.
#2




Join Date: Jul 2021
Location: Airport Lounges (Usually in ORD and LHR)
Programs: AA EXP 1MM, AY Gold, QR Gold, Hilton Diamond
Posts: 3,713
I recently discovered that my Samsung TV ignores the DNS server specified by my DHCP server and just uses 8.8.8.8. No wonder I still see ads on it. I had to set a NAT rule to override outbound port 53 and redirect it back to NextDNS.
It seems the only other devices on my network that do so are a couple of work-managed laptops.
It seems the only other devices on my network that do so are a couple of work-managed laptops.
#3
FlyerTalk Evangelist




Join Date: Apr 2009
Location: Bye Delta
Programs: AA EXP, UA Silver, HH Diamond, IHG Plat, Hyatt Plat, Marriott Titanium, Nat'l EE, Avis PC, Hertz PC
Posts: 16,637
I assume you already checked the TV’s network settings and it’s not configured to use a manually specified DNS server?
#4
 



Join Date: Nov 2000
Location: Upcountry Maui, HI
Posts: 13,712
Does it really need to be connected to the internet? Assume it has some connected services but do you use them or do you use an external Roku or Apple TV for example? Even if it has that built in you might be better off using an external one.
-David
-David
#5

Join Date: Jan 2015
Posts: 3,739
I agree. I prefer a regular TV/monitor and hooking up a mini PC to it. Gives me more flexibility and control. With a lot of these IoT devices you are at the mercy of the manufacturer and their focus is rarely on your security or privacy.
#6




Join Date: Jul 2007
Location: Brisbane, Australia
Programs: UA 1K/MM, Marriott Titanium, IHG Gold, Hertz PC, Avis PC
Posts: 8,531
You'll probably find that if you simply block it from getting to 8.8.8.8 and 8.8.4.4, or just block all outgoing port 53 except to where you want DNS to go, then it'll start working as you want. I've seen devices do this before - they try 8.8.8.8 or similar, but if they can't get to there then they'll use what DHCP has told them to use.
#7
Original Poster
FlyerTalk Evangelist



Join Date: Nov 2002
Location: ORD
Posts: 14,773
You'll probably find that if you simply block it from getting to 8.8.8.8 and 8.8.4.4, or just block all outgoing port 53 except to where you want DNS to go, then it'll start working as you want. I've seen devices do this before - they try 8.8.8.8 or similar, but if they can't get to there then they'll use what DHCP has told them to use.
eh, if I’m going to set a rule in the router I’ll just force everything to NextDNS.
#8

Join Date: Jan 2015
Posts: 3,739
Out of curiosity, how do you find them? Are you using the free version? I haven't tried figuring out how many DNS queries my network makes but I would also need to figure out how to segregate my IoT stuff (right now a few cameras but would be willing to add a few others) from my regular network.
#9
Original Poster
FlyerTalk Evangelist



Join Date: Nov 2002
Location: ORD
Posts: 14,773
Out of curiosity, how do you find them? Are you using the free version? I haven't tried figuring out how many DNS queries my network makes but I would also need to figure out how to segregate my IoT stuff (right now a few cameras but would be willing to add a few others) from my regular network.
I found them by setting the router to log anything outbound on port 53 since DHCP hands out the router as the DNS server. Our work laptops also ignore the DHCP settings, so I let them use the DNS they want to. But the TV was always hitting 8.8.8.8 even though I triple-checked it is set to use DNS from DHCP. If/when most things start using DNS over HTTPS or TLS, I'm not sure how I'd find them.
I put most IoT stuff on a separate vlan. Sonos and Apple TV are the exceptions - it was too hard to get them to work across VLANs with my phone.
#10
FlyerTalk Evangelist




Join Date: Apr 2001
Location: Denver, CO
Programs: UA Silver, Bonvoy Gold, Hyatt Discoverist
Posts: 23,192
Not that Roku devices are any better, but I disable the network connections on the smart TV and go through the Roku. I will occasionally plug in an ethernet cable on the TV to check for firmware updates.
#11
FlyerTalk Evangelist




Join Date: Jun 2004
Location: LON, ACK, BOS..... (Not necessarily in that order)
Programs: **Mucci Diamond Hairbrush** - compared to that nothing else matters (+BA Bronze)
Posts: 15,945
Is that not normal now, am I showing my age? I dont want someone else knowing what Im watching and thats what these tvs are reporting to someone, and then showing me adverts based on that info.
#12

Join Date: Jan 2015
Posts: 3,739
I dont have my telly connected to anything other than a satellite dish and an aerial for Digital Terrestrial Television. When I was looking at possibly replacing the CRT in the bedroom, I had a look round an electronics shop and found the focus is on connected now. A sales associate tried to sell me on the benefits of hooking my tv to the internet. I wasnt convinced in the slightest and it appeared from his facial expressions that he thought I was odd for not hooking it up. There wasnt much of an answer to If I dont watch streaming services whats the point I do have Amazon Prime for the next day free delivery but I use the video side of that at work during breaks as we dont have a television in our pokey staff room.
Is that not normal now, am I showing my age? I dont want someone else knowing what Im watching and thats what these tvs are reporting to someone, and then showing me adverts based on that info.
Is that not normal now, am I showing my age? I dont want someone else knowing what Im watching and thats what these tvs are reporting to someone, and then showing me adverts based on that info.
#14




Join Date: Jul 2007
Location: Brisbane, Australia
Programs: UA 1K/MM, Marriott Titanium, IHG Gold, Hertz PC, Avis PC
Posts: 8,531

