Data

What we know, and what we do not.

Every entry carries a source and a stated consequence. The gaps are listed too, because a catalogue that hides its holes is not much use to anyone deciding whether to trust it.

209

documented endpoints across 15 vendors

73

domains that break a television, published as an allowlist

0

crowdsourced reports merged. A row is published once five separate contributors have reported it.

By purpose

PurposeEntriesSafe to block
Content recognition10all
Advertising40all
Telemetry and diagnostics8786 of 87
Needed for the device to work43none
Firmware updates17none
Content delivery6none
Time synchronisation6none

By vendor

VendorBlockableDo not blockRecognition endpoints
amazon219none documented
apple1111none documented
google78none documented
hisense14none documented
lg2591
multiple12none documented
panasonic33none documented
philips33none documented
roku1721
samsung28133
sharp02none documented
sony942
toshiba10none documented
vizio533
xiaomi40none documented

The do-not-block list

The part of this catalogue with no good equivalent elsewhere. A blocklist is easy to write. Working out which entries break the app store, the firmware updater, the programme guide or the clock takes evidence, and several widely used lists get it wrong.

DomainBlocking it breaks
api.amazon.comThe device stops working. PETS 2021 lists this as required, and it also appears on their non-required list because it multiplexes both kinds of traffic. Multiplexed hosts cannot be blocked at DNS level without collateral damage.
unagi-eu.amazon.comThe device stops working. Classified required by PETS 2021.
mas-ext.amazon.comApps cannot be installed.
amazonadsi-a.akamaihd.netApp installation and updates fail.
softwareupdates.amazon.comFirmware updates fail.
ftv-smp.ntp-fireos.comThe clock drifts and certificate validation starts failing.
2.android.pool.ntp.orgThe clock drifts and certificate validation starts failing.
amazonalexa.comAlexa voice control stops working.
amazonaws.comWide collateral damage. Perflyst warns that device push messaging uses per-device certificates on shared AWS address space, so a blanket block takes out unrelated services.
mesu.apple.comSoftware updates fail.
gdmf.apple.comSoftware updates fail.
gs.apple.comSoftware updates and activation fail.
albert.apple.comDevice activation fails, which can leave a factory-reset Apple TV unusable.
itunes.apple.comThe App Store and media playback stop working.
apps.apple.comThe App Store stops working.
mzstatic.comApp Store artwork stops loading.
ocsp.apple.comCertificate validation fails, which can break app launches.
valid.apple.comCertificate validation fails.
push.apple.comPush notifications and several system services stop working.
guzzoni.apple.comSiri stops working. Block it deliberately if you do not want Siri.
googleapis.comPlay Store, app updates, DRM licensing and sign-in all fail. The three platform telemetry hosts under this domain are listed individually above. Block those, not the parent.
play.google.comThe Play Store stops working.
gvt1.comApp downloads and updates fail.
android.apis.google.comDevice check-in and account sync fail.

Showing 24 of 73.The full list, in AdGuard allowlist syntax.

Where our data is thin

Computed from the catalogue rather than asserted, so this section cannot quietly go stale while coverage stays poor.

VendorBlockable entries
sharp0
hisense1
multiple1
toshiba1
panasonic3
philips3
xiaomi4
vizio5
google7

The clearest gap is Google and Android TV. There is no HaGeZi native blocklist for that platform, the community has isolated only three platform telemetry hostnames, and Google's own telemetry shares domains with hosts that the Play Store and DRM need. If you own a Google TV and can capture its traffic, that is the single most useful contribution available.

Open questions

Things the research could not establish. Each is a good first contribution, and each is the reason a corresponding claim is absent from the guides rather than hedged.

  • Three figures circulate widely with no primary source: a 50-hour webOS developer session, a two-to-three month Tizen certificate expiry, and the claim that firmware updates silently re-enable content recognition. We publish none of them. The third is measurable, and measuring it would be an original finding.
  • Whether Samsung and LG televisions use hardcoded DNS-over-HTTPS endpoints. The only source making specific claims has unpublished captures and reads as generated content, so we do not cite it.
  • Almost nobody publishes hardcoded IP addresses, the ones a television dials without a DNS lookup. Two addresses from one rooted set is the state of public knowledge, and DNS filtering cannot touch them.
  • Per-manufacturer availability of the Private DNS setting on Android TV, which has no interface in stock builds.
  • Menu paths for Philips Titan OS, Panasonic My Home Screen, and several console platforms.
  • Whether the widely documented VPN consent dialog trap on Google TV also applies to Fire OS. It matters because removing that package permanently prevents any traffic observer from working.

Licences

WhatLicenceWhy
BlocklistsCC0 1.0Maximum uptake. If another list wants to absorb these entries, it should not have to ask or attribute.
Endpoint catalogue and guidesCC BY 4.0Reuse freely with credit.
Report corpusODbL 1.0Following Exodus Privacy. Volunteers contributed observations about their own homes, so derivatives should stay open to them.
CodeMITNo reason to restrict it.

Browse the dataAdd to it