On Tue, Sep 15, 2026 at 06:52:52AM +0000, Lari Huttunen wrote: > Hi all, > > I recently wrote a post about using OpenBSD to tame an LG WebOS Smart TV > by neutralizing its background telemetry, ACR tracking, and ad delivery. > > The setup relies entirely on base tools: pf to force-redirect evasive > outbound DNS (rdr-to), local unbound for DNS sinkholing, and an > instrumented dhcpd. Beyond the privacy wins, failing fast at the network > edge gives the TV's underpowered CPU a break from all the background > tracking overhead, making the UI noticeably snappier. > > Link to the full write-up: > https://fabricati-diem.inform.social/post/deshittification-as-a-service/ > > Many thanks to the developers and community for building and maintaining > such a rock-solid, well-integrated base ecosystem.
Hi all, A quick update for those interested in network instrumentation of untrusted hardware using an OpenBSD gateway. I have since published two follow-up write-ups examining how the WebOS operating system reacts when its telemetry channels are blocked at the network edge. Part 2 looks at how WebOS blocks access to the LG Content Store with artificial error codes when tracking endpoints fail to resolve: https://fabricati-diem.inform.social/post/deshittification-as-a-service-part2-bypassing-the-app-store-gatekeeper/ Part 3 analyzes a stateful cold-boot kill switch using packet captures taken on the gateway. When telemetry is blocked, the OS actively weaponizes its TCP stack by sending RST packets with zero window size to abort active streams from high-value targets like Netflix: https://fabricati-diem.inform.social/post/deshittification-as-a-service-part3-the-cold-boot-consent-trap-in-three-acts/ Hopefully these serve as a useful case study on using OpenBSD base tools like pf, unbound and tcpdump to observe and enforce network policies against hostile client hardware. Best regards, Lari Huttunen -- Inforta Ltd | "Connecting you to expert insights, anytime, anywhere." https://inform.social/about/

