← Back
furkan-bayrak

furkan-bayrak/lg-tv-blocklist

Curated DNS blocklist for LG webOS TV telemetry, ads and phone-home traffic (safe + strict tiers)

View on GitHub ↗
adguard-homeblocklistdnslg-tvpi-holeprivacywebos
Stars
236
Forks
6
Watchers
236
Open issues
2
Contributors
5
Language
Python
License
Creative Commons Attribution 4.0 International
Default branch
main
Created Sep 9, 2026Updated Sep 28, 2026

Star growth

Today—
This week—
This month—

Star history will appear here once this repo has been tracked for a couple of days.

README

LG TV Blocklist

An evidence-annotated DNS blocklist for LG webOS TV telemetry — the data your TV sends home about what you watch and do — plus ads and phone-home traffic. It is for LG TV owners who run a DNS blocker (Pi-hole, AdGuard Home, NextDNS) and want the TV to stop reporting home without breaking the apps they use.

Not affiliated with LG Electronics. LG is a trademark of LG Corp.

Why trust this list

Built by watching a real LG G1's network traffic and DNS logs, cross-checked against public reports. Every entry notes what it blocks and the evidence behind it — observation, not speculation. Method and replication steps: docs/methodology.md.

Which list should I use?

SAFE STRICT
Blocks Telemetry, ads, and ACR (Automatic Content Recognition — the TV's "what are you watching" reporting) Everything in SAFE, plus firmware OTA (over-the-air) updates, ThinQ cloud sync, and LG Channels
For Almost everyone Privacy-focused users who want the TV to fully stop talking to LG
Cost Streaming apps, Content Store, and app updates keep working (verified on an LG G1) Those services stop working on purpose

What breaks in STRICT (read this):

Feature SAFE STRICT
Netflix / Prime / HBO / YouTube works works
LG Content Store works may degrade (carve-out recipe)
Firmware OTA updates works blocked
ThinQ app / voice assistant cloud sync works blocked
LG Channels works blocked
LG account login works may fail

Install

Pick a tier above, then load the matching file into your blocker. Step-by-step walkthrough per blocker, with checks and uninstall steps: docs/install.md.

Your blocker SAFE STRICT
Pi-hole (v6) safe-domains.txt strict-domains.txt
AdGuard Home safe-adblock.txt strict-adblock.txt
dnsmasq safe-dnsmasq.txt strict-dnsmasq.txt
Rooted TV /etc/hosts safe-hosts.txt strict-hosts.txt

NextDNS has no custom list URLs, and its web UI denylist takes one domain per entry: add a zone anchor itself (lgtvcommon.com) for whole-family reach, or bulk-add a list file with scripts/nextdns_sync.py through the free API (install steps). Unbound cannot read the domains file as-is: it needs conversion to local-data entries (recipe). uBlock Origin is a browser extension: it can subscribe to the adblock file for your browser, but it does not cover your TV.

Checksums: SHA256SUMS. Not in Germany? The exact-name lists only cover the regions present — see the region FAQ and scripts/localize.py.

The regex files cover the audited two-letter region prefixes. Two optional extras for Pi-hole: safe-wildcard.txt and strict-wildcard.txt. The safe one covers all country versions of a server in one line (de., fr., jp., ...), wherever you are. The strict one goes further and blocks whole server families, including parts we have never seen. Add them to Pi-hole's Regex filters; as a normal blocklist they won't work. AdGuard Home can use them too (wrap each line in slashes); NextDNS can't do regex, so check the FAQ for the closest thing. They get regenerated with every list change; the # Updated: header shows the date of the file you are looking at, and the update table covers what refreshes by itself and what you re-paste by hand. Full details in the FAQ.

Rooted TV (webosbrew / Homebrew Channel): mirror the -hosts.txt entries into /etc/hosts; a webosbrew init.d hook (a boot-time script) can rewrite that file at every boot (it lives in RAM and resets on reboot — mechanism: webosbrew filesystem-overlays). Mirror src/safe.txt, or src/strict.txt for the full lockdown. Separately, examples/webos-hooks/ ships a boot hook that forces all TV DNS through your resolver and drops encrypted DNS (DoT/DoQ, port 853) — the fix for the hardcoded-resolver bypass in caveat 1. Rollback and caveats: hook README.

Clock stuck at 2021-01-01 after a power loss? Blocking LG's time-sync can leave a cold-booted TV unable to fix its clock, which breaks strict-TLS downloads (e.g. Homebrew Channel error (0)). examples/webos-hooks/04-sync-clock.sh sets the clock from an HTTP Date: header at boot — details in the hook README.

The two caveats

  1. LG hardcodes public resolvers. webOS daemons have been observed using 8.8.8.8 / 1.1.1.1 directly, and can use encrypted DNS, so a DNS blocklist alone is not a guarantee. Redirect outbound port 53 to your resolver and block port 853 at your firewall; on a rooted TV the DNS-egress hook does it on-device. A hosts file alone is not enough either — some daemons ignore it and query the TV's built-in DNS resolver directly.
  2. Exact names, not wildcards. Entries name specific hosts, so whole-family coverage depends on enumeration. Exceptions to the exact-name rule: the shipped -adblock.txt lists match subdomains via ||name^, the -dnsmasq.txt files match them with address=/name/0.0.0.0, and the optional -wildcard.txt regex files generalise the audited two-letter region prefixes. They work wherever regex rules are supported (Pi-hole, AdGuard Home); the strict one also blocks whole server families. If your TV talks to an LG domain that is not on the list, open a new-domain issue — that is exactly how the list grows.

FAQ

  • Which tier should I use? SAFE for almost everyone; STRICT if you want the TV to fully stop talking to LG.
  • Will this break Netflix / Prime / HBO / YouTube? No — verified on an LG G1.
  • My TV ignores my Pi-hole / AdGuard. Why? webOS has a built-in DNS resolver and hardcoded fallback DNS; fix it at the router, or use the rooted hook. To check that the resolver itself blocks the listed domains, run scripts/check_blocking.py.
  • I'm not in Germany — do the lists work? STRICT's adblock and dnsmasq lists are region-complete; the exact-name lists can be adapted with scripts/localize.py --region <cc>.
  • I want STRICT but keep the LG Content Store. See the carve-out recipe.
  • Why doesn't SAFE block all of lge.com? That would kill the Content Store, updates, and account login along with the telemetry.

Full list: docs/faq.md.

Dig deeper

  • Methodology — how the data was collected and how to replicate it, including a firmware-diff recipe: docs/methodology.md.
  • Upstream tracker — where these domains were submitted to community blocklists: docs/upstream.md.
  • Source of truth — annotated lists: src/safe.txt, src/strict.txt, src/zones.txt. The comments tell you what every entry does and the evidence behind it, e.g. snu.lge.com # STRICT: firmware OTA check server.
  • Contributing — evidence rules and how to add a domain, edit src/ only (CI regenerates the lists): CONTRIBUTING.md (templates: new domain, breakage).
  • Join as a maintainer — LG runs dozens of webOS versions and regional endpoints; captures or query logs from a C-series, G-series, or other model are exactly what this needs. Open an issue or submit a PR.

License

Content and generated lists: CC BY 4.0. Scripts and workflows: MIT.