Earlier quoted context omitted.
Get a raspberry pi and setup pihole with wireguard and dnscrypt-proxy. Get a hostname and basically tunnel your DNS requests to that pihole. Use Firefox and signal instead of say chrome. Disable the assistant and be aware of the privacy controls of your google account. Looking at the DNS requests made so far, it doesn't seem that much worse than an ipad or iphone. I think it depends on what you are also keeping priva…
Why would you tunnel your DNS requests when you can just switch DNS on the phone to a filtering one and also use blocklists, IE. with Blokada? Unless you route everything, not only default DNS, through the VPN, any app can just hardcode its own DNS ip and if you route everything through the VPN Blokada will do exactly the same but without an extra hop. Sounds terribly complicated for something that gives less securit…
It's less secure and likely more privacy problems trusting a service with Blokada compared with my own pihole.
My own pihole is accessible wherever I want, I know who has the logs for the DNS requests performed by my pihole which is done over DNS over HTTPS.
The DNS requests are made securely through wireguard and just those requests.
There is no extra hop?