Skip to content
DnsLister Forum

Where domain hunters compare notes

Trying to limit LG TV G4 spying

What I did:

Physical & TV Settings (LG G4)

  • Chassis Microphone: Switched the physical microphone slider on the bottom of the TV frame to OFF.
  • Remote Microphone: Disabled voice interaction features and stopped using the Magic Remote microphone button.
  • Network Interface: Disconnected and "forgot" the Wi-Fi network on the TV, retaining only the wired connection via the USB Ethernet adapter.
  • QuickStart+: Disabled.
  • Content Recommendations: Disabled.
  • webOS User Agreements: Declined non-essential agreements (Viewing Information, Voice Information, Interest-Based Advertising).

MikroTik Router Configuration

  • Layer 2 Bridge Separation: Removed interface ether4 from the default bridge interface.
  • Dedicated Gateway IP: Assigned 192.168.60.1/24 to interface ether4. Separate from my main home network.
  • DHCP IP Pool: Created IP pool pool-tv with range 192.168.60.10-192.168.60.50.
  • Dedicated DHCP Server: Created DHCP server dhcp-tv bound to ether4.
  • DHCP Network Settings: Configured subnet 192.168.60.0/24 with gateway 192.168.60.1 and DNS server my Pihole.
  • Interface List: Created interface list GUEST_IOT and added ether4 as a member.
  • Reverse Proxy Pinhole: Added firewall forward filter rule allowing TCP traffic from the TV subnet to reverse proxy on ports 80, 443 so I can use my Jellyfin (it was way too slow when accessing via the public domain.
  • Pi-hole DNS Pinhole: Added firewall forward filter rules allowing UDP and TCP traffic from 192.168.60.0/24 to Pi-hole on port 53.
  • LAN Isolation Rule: Added firewall forward filter rule dropping all traffic from 192.168.60.0/24 to 192.168.50.0/24, placed below the specific allow rules.
  • Router Management Protection: Added firewall input filter rule dropping traffic from ether4 targeting ports 80, 443, 8291, 22.
  • Encrypted DNS Block: Added firewall forward filter rules dropping TCP and UDP traffic on port 853 (DoT / DoQ) originating from 192.168.60.0/24.
  • Port 53 NAT Redirection: Added firewall dst-nat rules intercepting external UDP and TCP port 53 queries from 192.168.60.0/24 and redirecting them to 192.168.50.155.

Pi-hole & DNS Configuration

  • Blocklist: Applied HaGeZi's LG webOS Tracker blocklist to sinkhole LG telemetry and ad endpoints.
  • Split-Horizon DNS Record: Added a Local DNS entry pointing jelly.domain.com directly to reverse proxy IP address.
  • Cross-Subnet Listening: Changed Pi-hole DNS Interface Settings to "Permit all origins" to answer requests from 192.168.60.0/24.

With these applied how much more private is my LG TV usage now? I wanted to ask some opinions here.

Source: r/GamersNexus · by /u/huq_mu

Leave a Reply

Your email address will not be published. Required fields are marked *