No description
  • Python 53.1%
  • HTML 45.4%
  • Dockerfile 1.5%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
jdg 202088b588 Least privilege: cap_drop ALL + no-new-privileges on oauth2-proxy (applied 2026-10-05)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 18:31:59 -04:00
templates Add a comparison baseline and third-party analytics classification 2026-09-17 10:41:56 -04:00
.env.enc Add a comparison baseline and third-party analytics classification 2026-09-17 10:41:56 -04:00
.gitignore tv-watch: a running record of what the TVs ask DNS for 2026-09-10 23:24:03 -04:00
.sops.yaml tv-watch: a running record of what the TVs ask DNS for 2026-09-10 23:24:03 -04:00
app.py Add a comparison baseline and third-party analytics classification 2026-09-17 10:41:56 -04:00
compose.yaml Least privilege: cap_drop ALL + no-new-privileges on oauth2-proxy (applied 2026-10-05) 2026-10-07 18:31:59 -04:00
Dockerfile tv-watch: a running record of what the TVs ask DNS for 2026-09-10 23:24:03 -04:00
oauth2-proxy.cfg.enc tv-watch: send PKCE, because the pocket-id client requires it 2026-09-10 23:48:27 -04:00
README.md tv-watch: a running record of what the TVs ask DNS for 2026-09-10 23:24:03 -04:00
requirements.txt tv-watch: a running record of what the TVs ask DNS for 2026-09-10 23:24:03 -04:00

tv-watch

Keeps a running record of what the LG TVs ask DNS for, and whether it was blocked. At https://tv.jonathan.gluck.dev behind pocket-id.

A snapshot of a DNS log proves very little — a television phoning home twice is noise. The point is the shape over days: is telemetry climbing, is the set probing the LAN, and now that the firewall blocks its external DNS, does it start trying harder?

Sources

Pi-hole, every POLL_SECONDS. The recent query log is pulled and rows for the watched clients kept, de-duplicated on Pi-hole's own query id so re-polling is idempotent and history accumulates.

Pi-hole v6's /api/queries?client= parameter is silently ignored by the server — verified 2026-09-10, a bogus IP returns a full page. Filtering has to happen here. Do not trust that parameter.

UniFi, the hit counter on the Block LG TV external DNS policy. It only ever increases, so the page reports the rate: a rising slope means the TV is actively retrying, which is the interesting signal rather than the total.

Classification

telemetry — LG's own reporting endpoints (lgtviot.com, nextlgsdp.com, lgsmartad.com, …). lan-scan — *.in-addr.arpa, i.e. the TV resolving names for other devices on the network. Everything else is other.

Netflix and app telemetry are deliberately excluded. That follows from using Netflix, not from owning the television, and counting it would overstate the case.

First measurement (2026-09-10)

609 queries in the first poll from the living-room C1: 517 LAN reverse lookups, 42 telemetry, 50 other. The set spends most of its DNS traffic enumerating the house.

  • Pi-hole regex denylist: (\.|^)lgtviot\.com$, (\.|^)nextlgsdp\.com$
  • UniFi policy Block LG TV external DNS — Internal→External, tcp_udp, ports 53 and 853, source the TVs' reserved IPs
  • Neither covers DNS-over-HTTPS (port 443, indistinguishable from web traffic) or hardcoded IPs. The firewall hit rate on this page is the early warning.