Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"unfiltered internet access"? How would you even know what to filter?

Block it entirely, and hope it that doesn't connect to your Samsung phone via Bluetooth or WiFi and use it as a proxy.



Some devices refuse to to operate if they can't make DNS queries.


Such devices should be retuned for a full refund. Vote with your wallet.


My devices that do this were bought off aliexpress for about a quarter the price of a reputable brand. They do function and I purchased them expecting I would have to do some finagleing to get them to work and not phone home.


Then they can exfiltrate data over DNS.


I mean, only if the DNS server is one run by the company in question.

I own nonzero such devices that hit 8.8.8.8 as an internet access sanity check so I have to keep just that IP allowed for them and block all other traffic.


DNS is a hierarchical protocol. You can exfiltrate data as long as the DNS server is resolving recursively.


Good to know. I didn't know that.

For my devices in question I can see the size and frequency of the requests in OpenWRT and doubt it's actually doing so.


Then give it a DNS server to look up.


Yes exactly.


I mean, at some point, victim-blaming does sound like the correct response here.

If the answer to your question involved giving money to Samsung, then you asked the wrong question, and you need to do better next time.


All I meant was that sometimes if you fully block a device it refuses to work, and you may need to selectively unblock just 8.8.8.8 for that device.

Obviously buying such a device is bad, but sometimes you get one for free or close to it and it's worth the hassle to not pay hundreds for a better one.


Services like ControlD and NextDNS have built in blocklists for IoT telemetry and bullshit. I'm sure it's easy to do it with PiHole as well.

I use ControlD and it's blocking 38% of all DNS requests in my household. 8% of that is IoT telemetry. It's unbelievable how much of this bullshit is built into the products we use.


What I've done for the small handful of wifi connected devices I have is to have them connect to "internet sharing" from my laptop's wifi.

Naturally when my laptop is using its wifi to create a hotspot it isn't actually connected to the internet, so they never actually get access to the internet.

(Doesn't work if you actually want the internet, and not just wifi, related features of course)


IIRC there were some Pihole blocking lists for Samsung, Apple and Microsoft etc.


Give them access to a segregated home network.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: