Go Back  FlyerTalk Forums > Travel&Dining > Travel Technology
Reload this Page >

Naughty IoT ("Internet of Things") devices

Community
Wiki Posts
Search

Naughty IoT ("Internet of Things") devices

Thread Tools
 
Search this Thread
 
Old Aug 29, 2024 | 7:28 pm
  #1  
Original Poster
FlyerTalk Evangelist
Conversation Starter
All eyes on you!
20 Years on Site
 
Join Date: Nov 2002
Location: ORD
Posts: 14,773
Naughty IoT ("Internet of Things") devices

I recently discovered that my Samsung TV ignores the DNS server specified by my DHCP server and just uses 8.8.8.8. No wonder I still see ads on it. I had to set a NAT rule to override outbound port 53 and redirect it back to NextDNS.

It seems the only other devices on my network that do so are a couple of work-managed laptops.
KRSW likes this.
gfunkdave is offline  
Old Aug 29, 2024 | 8:01 pm
  #2  
S80
20 Nights
20 Countries Visited
1M
All eyes on you!
 
Join Date: Jul 2021
Location: Airport Lounges (Usually in ORD and LHR)
Programs: AA EXP 1MM, AY Gold, QR Gold, Hilton Diamond
Posts: 3,713
Originally Posted by gfunkdave
I recently discovered that my Samsung TV ignores the DNS server specified by my DHCP server and just uses 8.8.8.8. No wonder I still see ads on it. I had to set a NAT rule to override outbound port 53 and redirect it back to NextDNS.

It seems the only other devices on my network that do so are a couple of work-managed laptops.
I don't trust any device to get anything but an IP address from DHCP, everything else must be enforced (like DNS) and go through a router level VPN (vs device level).
S80 is offline  
Old Aug 30, 2024 | 11:35 pm
  #3  
FlyerTalk Evangelist
30 Countries Visited
1M
All eyes on you!
15 Years on Site
 
Join Date: Apr 2009
Location: Bye Delta
Programs: AA EXP, UA Silver, HH Diamond, IHG Plat, Hyatt Plat, Marriott Titanium, Nat'l EE, Avis PC, Hertz PC
Posts: 16,637
I assume you already checked the TV’s network settings and it’s not configured to use a manually specified DNS server?
javabytes is offline  
Old Aug 31, 2024 | 11:02 pm
  #4  
 
2M
All eyes on you!
25 Years on Site
 
Join Date: Nov 2000
Location: Upcountry Maui, HI
Posts: 13,712
Does it really need to be connected to the internet? Assume it has some connected services but do you use them or do you use an external Roku or Apple TV for example? Even if it has that built in you might be better off using an external one.

-David
pudgym29 and elCheapoDeluxe like this.
LIH Prem is offline  
Old Sep 3, 2024 | 9:42 am
  #5  
All eyes on you!
 
Join Date: Jan 2015
Posts: 3,739
I agree. I prefer a regular TV/monitor and hooking up a mini PC to it. Gives me more flexibility and control. With a lot of these IoT devices you are at the mercy of the manufacturer and their focus is rarely on your security or privacy.
crackjack, KRSW, Jimmie76 and 1 others like this.
StuckInYYZ is offline  
Old Sep 4, 2024 | 12:56 am
  #6  
2M
60 Nights
50 Countries Visited
15 Years on Site
 
Join Date: Jul 2007
Location: Brisbane, Australia
Programs: UA 1K/MM, Marriott Titanium, IHG Gold, Hertz PC, Avis PC
Posts: 8,531
Originally Posted by gfunkdave
I recently discovered that my Samsung TV ignores the DNS server specified by my DHCP server and just uses 8.8.8.8. No wonder I still see ads on it. I had to set a NAT rule to override outbound port 53 and redirect it back to NextDNS.
You'll probably find that if you simply block it from getting to 8.8.8.8 and 8.8.4.4, or just block all outgoing port 53 except to where you want DNS to go, then it'll start working as you want. I've seen devices do this before - they try 8.8.8.8 or similar, but if they can't get to there then they'll use what DHCP has told them to use.
HDQDD likes this.
docbert is offline  
Old Sep 4, 2024 | 8:51 pm
  #7  
Original Poster
FlyerTalk Evangelist
Conversation Starter
All eyes on you!
20 Years on Site
 
Join Date: Nov 2002
Location: ORD
Posts: 14,773
Originally Posted by docbert
You'll probably find that if you simply block it from getting to 8.8.8.8 and 8.8.4.4, or just block all outgoing port 53 except to where you want DNS to go, then it'll start working as you want. I've seen devices do this before - they try 8.8.8.8 or similar, but if they can't get to there then they'll use what DHCP has told them to use.

eh, if I’m going to set a rule in the router I’ll just force everything to NextDNS.
LIH Prem and pudgym29 like this.
gfunkdave is offline  
Old Sep 5, 2024 | 4:51 am
  #8  
All eyes on you!
 
Join Date: Jan 2015
Posts: 3,739
Originally Posted by gfunkdave
eh, if Im going to set a rule in the router Ill just force everything to NextDNS.
Out of curiosity, how do you find them? Are you using the free version? I haven't tried figuring out how many DNS queries my network makes but I would also need to figure out how to segregate my IoT stuff (right now a few cameras but would be willing to add a few others) from my regular network.
StuckInYYZ is offline  
Old Sep 5, 2024 | 8:20 am
  #9  
Original Poster
FlyerTalk Evangelist
Conversation Starter
All eyes on you!
20 Years on Site
 
Join Date: Nov 2002
Location: ORD
Posts: 14,773
Originally Posted by StuckInYYZ
Out of curiosity, how do you find them? Are you using the free version? I haven't tried figuring out how many DNS queries my network makes but I would also need to figure out how to segregate my IoT stuff (right now a few cameras but would be willing to add a few others) from my regular network.
Nah, I pay the $20/year. It's a handy way to block ads and malware on my network, my parents', and my mother in law's. I went through the free 100k or 300k queries in a week or two.

I found them by setting the router to log anything outbound on port 53 since DHCP hands out the router as the DNS server. Our work laptops also ignore the DHCP settings, so I let them use the DNS they want to. But the TV was always hitting 8.8.8.8 even though I triple-checked it is set to use DNS from DHCP. If/when most things start using DNS over HTTPS or TLS, I'm not sure how I'd find them.

I put most IoT stuff on a separate vlan. Sonos and Apple TV are the exceptions - it was too hard to get them to work across VLANs with my phone.
gfunkdave is offline  
Old Sep 11, 2024 | 9:33 am
  #10  
FlyerTalk Evangelist
Community Builder
Active Streak: 30 Days
All eyes on you!
25 Years on Site
 
Join Date: Apr 2001
Location: Denver, CO
Programs: UA Silver, Bonvoy Gold, Hyatt Discoverist
Posts: 23,192
Not that Roku devices are any better, but I disable the network connections on the smart TV and go through the Roku. I will occasionally plug in an ethernet cable on the TV to check for firmware updates.
pseudoswede is online now  
Old Sep 14, 2024 | 5:04 pm
  #11  
FlyerTalk Evangelist
10 Countries Visited
1M
All eyes on you!
20 Years on Site
 
Join Date: Jun 2004
Location: LON, ACK, BOS..... (Not necessarily in that order)
Programs: **Mucci Diamond Hairbrush** - compared to that nothing else matters (+BA Bronze)
Posts: 15,945
Originally Posted by LIH Prem
Does it really need to be connected to the internet? Assume it has some connected services but do you use them or do you use an external Roku or Apple TV for example? Even if it has that built in you might be better off using an external one.

-David
I dont have my telly connected to anything other than a satellite dish and an aerial for Digital Terrestrial Television. When I was looking at possibly replacing the CRT in the bedroom, I had a look round an electronics shop and found the focus is on connected now. A sales associate tried to sell me on the benefits of hooking my tv to the internet. I wasnt convinced in the slightest and it appeared from his facial expressions that he thought I was odd for not hooking it up. There wasnt much of an answer to If I dont watch streaming services whats the point I do have Amazon Prime for the next day free delivery but I use the video side of that at work during breaks as we dont have a television in our pokey staff room.

Is that not normal now, am I showing my age? I dont want someone else knowing what Im watching and thats what these tvs are reporting to someone, and then showing me adverts based on that info.
Jimmie76 is offline  
Old Sep 14, 2024 | 5:52 pm
  #12  
All eyes on you!
 
Join Date: Jan 2015
Posts: 3,739
Originally Posted by Jimmie76
I dont have my telly connected to anything other than a satellite dish and an aerial for Digital Terrestrial Television. When I was looking at possibly replacing the CRT in the bedroom, I had a look round an electronics shop and found the focus is on connected now. A sales associate tried to sell me on the benefits of hooking my tv to the internet. I wasnt convinced in the slightest and it appeared from his facial expressions that he thought I was odd for not hooking it up. There wasnt much of an answer to If I dont watch streaming services whats the point I do have Amazon Prime for the next day free delivery but I use the video side of that at work during breaks as we dont have a television in our pokey staff room.

Is that not normal now, am I showing my age? I dont want someone else knowing what Im watching and thats what these tvs are reporting to someone, and then showing me adverts based on that info.
If a sales person did that to me, I'd likely walk out of the store without purchasing anything. The "It's easier and more convenient" argument doesn't work for me. Yes it's a bit more effort, but if it makes things more difficult for someone to trace me, then I'm all for it.
pudgym29 likes this.
StuckInYYZ is offline  
Old Sep 14, 2024 | 7:49 pm
  #13  
10 Countries Visited
All eyes on you!
15 Years on Site
 
Join Date: Jan 2010
Location: SFO
Posts: 2,139
My DHCP server does not give my Sony TV a gateway. That way I can still control it via IP and Home Assistant.

Streaming is done with a Roku, and ads are blocked by a PIHole.
returnoftheyeti is offline  
Old Sep 15, 2024 | 11:16 am
  #14  
2M
60 Nights
50 Countries Visited
15 Years on Site
 
Join Date: Jul 2007
Location: Brisbane, Australia
Programs: UA 1K/MM, Marriott Titanium, IHG Gold, Hertz PC, Avis PC
Posts: 8,531
Originally Posted by returnoftheyeti
Streaming is done with a Roku
The same Roku that likely does more to track your behavior than your TV does? I'm not sure that's a win...
gfunkdave likes this.
docbert is offline  
Old Sep 15, 2024 | 6:12 pm
  #15  
10 Countries Visited
All eyes on you!
15 Years on Site
 
Join Date: Jan 2010
Location: SFO
Posts: 2,139
Originally Posted by docbert
The same Roku that likely does more to track your behavior than your TV does? I'm not sure that's a win...
Its all (mostly 98%) blocked by the PiHole. I don't get ads at all on my Roku
returnoftheyeti is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.