Hi, Also a nice tool in this context is veb(4)/vport(4): you can assign a tag on all traffic originating from a specific MAC address like so (note that this is for a veb(4) rulefile, not pf.conf):
pass in on igc0 src 0c:ca:fb:12:a5:d8 tag localonly ...and because the tag set by veb(4) is visible to pf(4) you can then do something like this in pf.conf: block out quick on $ext_if tagged localonly At that point the TV can't send anything to the outside world directly no matter the transport (IPv4/IPv6) or the protocol, but the TV can still participate in the local network. Indirect communication is still possible, for example via DNS requests to the local resolving proxy that encode information; those will ultimately end up at the content DNS server of the domain owner. Regards, Jurjen Oskam Op zo 27 sep 2026 om 07:50 schreef Lari Huttunen <[email protected]>: > On Tue, Sep 15, 2026 at 06:52:52AM +0000, Lari Huttunen wrote: > > Hi all, > > > > I recently wrote a post about using OpenBSD to tame an LG WebOS Smart TV > > by neutralizing its background telemetry, ACR tracking, and ad delivery. > > > > The setup relies entirely on base tools: pf to force-redirect evasive > > outbound DNS (rdr-to), local unbound for DNS sinkholing, and an > > instrumented dhcpd. Beyond the privacy wins, failing fast at the network > > edge gives the TV's underpowered CPU a break from all the background > > tracking overhead, making the UI noticeably snappier. > > > > Link to the full write-up: > > https://fabricati-diem.inform.social/post/deshittification-as-a-service/ > > > > Many thanks to the developers and community for building and maintaining > > such a rock-solid, well-integrated base ecosystem. > > Hi all, > > A quick update for those interested in network instrumentation of > untrusted hardware using an OpenBSD gateway. > > I have since published two follow-up write-ups examining how the WebOS > operating system reacts when its telemetry channels are blocked at the > network edge. > > Part 2 looks at how WebOS blocks access to the LG Content Store with > artificial error codes when tracking endpoints fail to resolve: > > > https://fabricati-diem.inform.social/post/deshittification-as-a-service-part2-bypassing-the-app-store-gatekeeper/ > > Part 3 analyzes a stateful cold-boot kill switch using packet captures > taken on the gateway. When telemetry is blocked, the OS actively > weaponizes its TCP stack by sending RST packets with zero window size to > abort active streams from high-value targets like Netflix: > > > https://fabricati-diem.inform.social/post/deshittification-as-a-service-part3-the-cold-boot-consent-trap-in-three-acts/ > > Hopefully these serve as a useful case study on using OpenBSD base tools > like pf, unbound and tcpdump to observe and enforce network policies > against hostile client hardware. > > Best regards, > > Lari Huttunen > -- > Inforta Ltd | "Connecting you to expert insights, anytime, anywhere." > https://inform.social/about/ > >

