Hi,

Also a nice tool in this context is veb(4)/vport(4): you can assign a tag
on all traffic originating from a specific MAC address like so (note that
this is for a veb(4) rulefile, not pf.conf):

pass in on igc0 src 0c:ca:fb:12:a5:d8 tag localonly

...and because the tag set by veb(4) is visible to pf(4) you can then do
something like this in pf.conf:

block out quick on $ext_if tagged localonly

At that point the TV can't send anything to the outside world directly no
matter the transport (IPv4/IPv6) or the protocol, but the TV can still
participate in the local network.

Indirect communication is still possible, for example via DNS requests to
the local resolving proxy that encode information; those will ultimately
end up at the content DNS server of the domain owner.

Regards,

Jurjen Oskam

Op zo 27 sep 2026 om 07:50 schreef Lari Huttunen <[email protected]>:

> On Tue, Sep 15, 2026 at 06:52:52AM +0000, Lari Huttunen wrote:
> > Hi all,
> >
> > I recently wrote a post about using OpenBSD to tame an LG WebOS Smart TV
> > by neutralizing its background telemetry, ACR tracking, and ad delivery.
> >
> > The setup relies entirely on base tools: pf to force-redirect evasive
> > outbound DNS (rdr-to), local unbound for DNS sinkholing, and an
> > instrumented dhcpd. Beyond the privacy wins, failing fast at the network
> > edge gives the TV's underpowered CPU a break from all the background
> > tracking overhead, making the UI noticeably snappier.
> >
> > Link to the full write-up:
> > https://fabricati-diem.inform.social/post/deshittification-as-a-service/
> >
> > Many thanks to the developers and community for building and maintaining
> > such a rock-solid, well-integrated base ecosystem.
>
> Hi all,
>
> A quick update for those interested in network instrumentation of
> untrusted hardware using an OpenBSD gateway.
>
> I have since published two follow-up write-ups examining how the WebOS
> operating system reacts when its telemetry channels are blocked at the
> network edge.
>
> Part 2 looks at how WebOS blocks access to the LG Content Store with
> artificial error codes when tracking endpoints fail to resolve:
>
>
> https://fabricati-diem.inform.social/post/deshittification-as-a-service-part2-bypassing-the-app-store-gatekeeper/
>
> Part 3 analyzes a stateful cold-boot kill switch using packet captures
> taken on the gateway. When telemetry is blocked, the OS actively
> weaponizes its TCP stack by sending RST packets with zero window size to
> abort active streams from high-value targets like Netflix:
>
>
> https://fabricati-diem.inform.social/post/deshittification-as-a-service-part3-the-cold-boot-consent-trap-in-three-acts/
>
> Hopefully these serve as a useful case study on using OpenBSD base tools
> like pf, unbound and tcpdump to observe and enforce network policies
> against hostile client hardware.
>
> Best regards,
>
> Lari Huttunen
> --
> Inforta Ltd | "Connecting you to expert insights, anytime, anywhere."
> https://inform.social/about/
>
>

Reply via email to