---
title: 'I Stopped My Smart TV from Spying'
source: 'https://youtube.com/watch?v=oeqUHEp4sYM'
video_id: 'oeqUHEp4sYM'
date: 2026-08-26
duration_sec: 681
channel: 'Linus Tech Tips'
---

# I Stopped My Smart TV from Spying

> Source: [I Stopped My Smart TV from Spying](https://youtube.com/watch?v=oeqUHEp4sYM)

## Summary

The video discusses how smart TVs collect and transmit data, focusing on Automatic Content Recognition (ACR) and its privacy implications. It explains how ACR works, why turning it off may not be sufficient, and evaluates various countermeasures, concluding that the only surefire solution is to keep the TV offline.

### Key Points

- **TVs are data collection devices** [00:15] — TV manufacturers openly admit to losing money on hardware to build an install base for advertising, and they collect data via ACR to maximize shareholder value.
- **How ACR works** [03:32] — ACR takes screenshots and audio samples multiple times per second, converts them into digital fingerprints, and matches them against a database to serve targeted ads.
- **Limitations of turning off ACR** [04:55] — Turning off ACR may not be permanent; features can re-enable with updates, and encrypted data prevents auditing.
- **Future risks** [05:50] — Future risks include sending full screenshots and using AI to classify content, potentially leading to copyright enforcement.
- **Only unplugging works** [07:30] — DNS filtering and IP blocking are ineffective due to encryption and the vast number of IPs; the only surefire solution is to never connect the TV to the internet.

## Transcript

Would you look at all the data that's flying off of a typical smart TV? And all this one is doing over here is just sitting there in the program guide. And okay, sure. This is probably old news for many of you, but
I think what makes this conversation worth having again is the way that TV manufacturers aren't even pretending anymore. I mean, they're talking openly about losing money on TV hardware all just to get that sweet sweet install
base that they can use to sell advertising. And what better way to maximize shareholder value than to collect as much information about you as possible by monitoring everything that crosses your display and reporting it
back to HQ so you can better target those ads. The trouble is that solving this once AND FOR ALL
up with what the housewives are doing. And unfortunately, some of the simpler less violent solutions that mainstream outlets offer just don't seem to go far enough. So, let's talk about what's going on, what you can do about it, and
what you can't do. After some targeted advertising of our own from our sponsor. &gt;&gt; Bet you didn't expect to see me, Sasquatch, in an LTT video. Did you?
And you know, being blurry photos just doesn't pay like it used to. But thanks to boot.dev, I landed a job coding. And you can, too. Stick around to the end of the video to see if you can find a hidden code out there.
were working on this video, and it almost killed it, is that while we have our suspicions, we can't actually tell exactly what all of the traffic streaming off of our TV is. And that's because most of it is encrypted. That's
not necessarily a nefarious thing. That's just the internet in 2026. Everything uses SSL, or at least it should, and there are many innocuous reasons for a smart TV to transfer a ton of data. Program guides, preview clips,
he's a big fan of typewriters, by the way? Was that Spielberg? It doesn't matter. The point is that TV manufacturers have openly admitted that at least some of the traffic that your TV is sending back to the manufacturer
or to the software developer is quietly telling them exactly what's on your screen or coming out of your speakers. And they're using that information to make a lot of money. Most of the talk lately has been around
something that is generically called automatic content recognition or ACR. Finding this and turning it off on your TV though can be a little bit tricky since most brands refer to it euphemistically, giving it a name that
sounds less sinister than we're watching what you watch. Names like smart interactivity or live plus. This isn't a new thing, by the way. ACR is exactly how Shazam was able to identify that bop that was playing in
the food court way back in 2002. And they actually pioneered some of the ACR methods that have been used by the TV industry for the last 15 or so years. ACR works by automatically taking screenshots and audio samples.
Did you know your smart TV has mics in it? Cool, right? Uh anyway, they take these samples multiple times per second of whatever your TV is outputting, regardless of the source of the content. So it could just be Netflix on the
built-in app, but it could also be an HDMI feed from your Windows desktop or that your mom is always showing your fiance. All of that is getting slurped up and analyzed. Those samples then get turned
analyzed. Those samples then get turned into digital fingerprints and then sent off to be checked against a big database somewhere that has a catalog of basically all known content ever. And through the magic of technology, now you
get ads that are targeted to your demographic and your viewing habits. just helping you find your new favorite song. In an attempt to look inside these packets, we tried setting up multiple man-in-the-middle attacks to try to
break the encryption. But, because none of the TVs that we tested offered any certificates, we weren't able to convince them to encrypt our packets decode. And I know what you guys are thinking. Linus, you handsome dumbass,
just turn off ACR, problem solved. And yeah, you know what? That might work for today, and it might even work for tomorrow. There's a tech tip. Go ahead, go turn ACR off.
I'm worried that we are on an increasingly slippery slope here. I mean, look at the current state of Windows 11. We've seen multiple flat-out lies that have been told about the privacy and the security of features
like Windows Recall. And if someone were to tell you at this point, "Well, just turn off Recall, turn off Copilot. It's fine." You would laugh in their face features are just going to turn themselves back on again with the next
update, anyway. And I wouldn't even be mildly surprised to discover that major TV brands are just still collecting data after you turn these features off. After all, how would we audit it, given that all of the data is encrypted, anyway? I
also wouldn't be surprised if sometime soon ACR just becomes mandatory as part of the privacy agreement that we have to click through in order to unbrick our brand new televisions could also get much worse in the future.
Put on your tinfoil hats and follow along with me for a minute. Right now, it's these fingerprints, right? These relatively small hashes of screenshots or audio samples that get paired to known quantities. Bandwidth is cheap and
AI is getting way more ubiquitous. So, what would stop them then from just sending outright screenshots? I mean, a 4K image is easily under a megabyte with decent compression and we've already seen just how much data these things are
spewing back and forth. A few hundred extra kilobytes a second would just get lost in the noise while potentially giving brands unfiltered screenshots of mention a complete list of your favorite Linux ISOs. You know, things they have
absolutely no business seeing or knowing about and that they certainly can't be trusted with. Where AI fits into the picture is instead of having to compare these screenshots against known content in a database, they could classify quite
literally anything and all it would cost us is a few likes here and there. Wow. What a deal to make the line go up into the right. Then to take things further, imagine that there was a little piece of software in your next even smarter TV
that detects when you're watching something that you don't have a license Why should it let you watch that unauthorized content? stretch. I mean, there's already copy protection built into HDMI which as far
as I can tell is a major part of the reason that that standard has stayed so reason that that standard has stayed so ubiquitous in the AV space. So, Well, the only sure fire way to stop your TV
from phoning home is to never connect it to the internet. You plug in your Linux powered PC to an HDMI port and then just pretend you've got a dumb TV. To their credit, some TV manufacturers actually do support a pretty nice
feature where you can tell it, "Hey, ignore the smart home screen. I ain't using that, and go immediately to a particular HDMI input as soon as I power on the TV." That effectively will turn it into a dumb TV.
I know this sounds like an extreme solution, right? Couldn't you just use something like a Pi-hole or some other filtering DNS so the TV doesn't know where to send its data? That's a great idea, too. It's just that unfortunately,
it's about 10 years too late. First up, most of the TVs we tested didn't even allow us to manually set network settings. They rely on your router to provide that via DHCP. Second, though, even if you set your DHCP to tell a
device which DNS to use, as it turns out, you can't actually force the TV to use that DNS. I mean, I can't even count how many times Android devices have completely ignored DNS servers that I've told them to use.
Finally, it is no longer feasible to intercept and rewrite DNS traffic by simply watching for queries on good old port 53. The glory days of DNS shenanigans are long gone thanks to technologies like DoH, DoT, DoH3, and
DoQ, and probably some others that I'm forgetting. And guess what? It gets even worse. I mean, who says they need to use DNS at all? The TVs could simply have a list of IPs that are coded into them that they send data to, and then they
can update that list as they need. Well, no problem, you might say. Just block those IPs. All right, smart guy. Do you know which All right, smart guy. Do you know which of Amazon's 200 million or so IP
addresses are for Prime telemetry? Do you know which ones host the content know which ones serve little Timmy's soccer team webpage? And that's just Amazon's tiny percentage of the IPv4 space that makes up some 3.7
billion publicly addressable IPs. And then forget about IPv6. Are you guys really going to go through every single IP that your TV tries to talk to, block it, and then test to make sure that everything you want still
Nobody's got time for that. So, the only sure fire solution, well, other than that one, is to just unplug the thing. And if you have it on Wi-Fi, because it's the only way to be sure that it isn't connecting and isn't
That is the only way to be sure until they just go stick cellular modems in everything and use cheap overnight data rates.
countermeasure. On that cheerful note, um There's only one thing that'll make me feel better about this. &gt;&gt; Boot. Sasquatch again. Been in the squatching
game for 200 years, but you probably haven't seen old Bigfoot lately. That's because I changed careers. Shout out boot.dev. Back in the '70s, the only code I knew was Morse, but boot.dev taught me Python
and Go from start to finish. And I'm learning Linux and SQL next. It was fun, too. I was earning experience, leveling up, all while completing quests. Life's great now cuz you can't learn to code without building real projects. When I
heard from Stack Overflow that the median salary for back-end developers in the US is $100,000, I said to myself, "Mr. Foot, what are you doing trawling in the woods?" So, click the link in the description and use code LTTS to save
25% off your first month or year with boot.dev. check out the one we did on one of the last remaining brands that still makes dumb TVs, Sceptre.
