Recent threads here (blocking webOS with firewall rules, locking down an LG TV except for Home Assistant) mostly end in "just never connect it" or "block all egress". One user even found out the hard way that a full block makes webOS degrade on purpose (dev-mode logout, apps crawling, all snappy again once unblocked). I took the middle path and measured first: a 40-minute DNS+SNI capture of an EU OLED C1 (webOS 6.0) on the gateway itself.
Transparency up front: this was done pair-style with an AI agent (Claude). It drove the gateway captures, wrote the script and drafted this post. I'm flagging that prominently because you should be suspicious of AI-generated domain lists. That is exactly why every number here comes from an actual packet capture (not from the model's training data), why I verified the sinkhole with dig against my own controller, and why the gist documents how to reproduce the capture yourself instead of trusting my list.
Findings that might save you some time:
- The domain lists everyone copies (lgsmartad / lgappstv / alphonso) were never queried once. This device talks to
DE.nextlgsdp.com,DE.ibs.nextlgsdp.com(beacons) andEIC.tv.wiselg.com. - "These devices sneak around DNS": this one didn't. Every single DNS query went to the gateway resolver, no DoH, no DoT, no QUIC observed.
- UniFi's built-in Ad Blocking does not cover LG's own domains (verified: it blocked generic adtech while the LG beacons went straight through), and Domain Filtering has no API. But the official Integration API has a DNS-records endpoint, and an A record pointing at 0.0.0.0 is a sinkhole. Fully scriptable, idempotent, no extra hardware.
- Two traps: the API happily accepts wildcard records that dnsmasq then silently ignores (enumerate region prefixes instead), and firmware-update hosts (
*gfts*,snu.lge.com) live on multiple LG domains. Leave those reachable, especially with the webOS RCEs from the Gamers Nexus report still undisclosed.
Script + full write-up: https://gist.github.com/KallistoX/ca0413c63e58799ecdfc516b64d603ff
Caveat: n=1 device/firmware/region, opted out of everything in the settings. Verify with your own capture (tcpdump on the gateway, 30 minutes, port 53 + TLS ClientHellos; how-to in the gist). I've also contributed the observed domains to the hagezi blocklists (issue) for the Pi-hole/AdGuard crowd.
If you'd rather not run a random script: the API endpoint was found by pointing the LLM at the official UniFi API docs via mcp-unifi-applications (MCP server, read-only, no controller credentials). Your agent can build and adapt the sinkhole for your site directly.
TV belongs to my parents, hence the "red-button Mediathek apps must keep working" constraint instead of dumb-display.
Source: r/Ubiquiti · by /u/KallistoX