How did this make it to the front-page with 11 points by linking to " https://0.0.0.0:4000/blog/force-dns-pihole "? Do most people just vote based on the title?
Maybe we count this one as an art performance?
11–20 of 673 posts
How did this make it to the front-page with 11 points by linking to " https://0.0.0.0:4000/blog/force-dns-pihole "? Do most people just vote based on the title?
Maybe we count this one as an art performance?
How did this make it to the front-page with 11 points by linking to " https://0.0.0.0:4000/blog/force-dns-pihole "? Do most people just vote based on the title?
The title says something about the PiHole and the link is to 0.0.0.0. And it made it to the front page. Maybe we count this one as an art performance?
Looks like you meant to share this: https://labzilla.io/blog/force-dns-pihole
Oh yes sorry. I haven’t noticed it, don’t know what url I copied in my clipboard.
https://0.0.0.0:4000/blog/force-dns-pihole">
So some "Share" buttons may pick that up.
> some of these devices are using a sneaky tactic to bypass your PiHole entirely I don't think that it's malevolent on their part. Lots of ISP DNS are crappy. Hardcoding a reasonably reliable one saves them a lot of frustration and unnecessary technical support.
I’m responsible for a bunch of IoT hardware, and every firmware spec I write includes a note on not using the DNS servers provided via DHCP. While sure there are companies explicitly doing this to avoid filtering, at least in my case it’s because a significant proportion of DHCP servers are configured to send DNS to your ISP, and ISP provided DNS is almost universally terrible. They’ll ignore TTLs, rewrite NXDOMAIN r…
I am very suspicious of the push for https and the like. I feel it is mainly about hiding the payload from me not any third party.
Going to be a sad day for those advertisers when the DNS project gets killed by Google. Hopefully they are smart enough to set a alternate as well.
The next step will be hard-coded DoH server IPs. Sly owners will NAT those to a transparent MiTM proxy.
Then device manufacturers will counter with certificate pinning for DoH. That will be "game over", and the device manufacturers win. (It'll be a double-win, actually. It will put a hard "expiration date" on the device's functionality when a link in the PKI chain expires.)
I believe the owner of a device has right to control the device's network traffic (and, more generally, control of the code running on the device). Business models that rely on taking away an owner's control of their rightfully-purchased general purpose computing devices are really rental models and should be handled as such.
I eschew these kinds of devices, use or create self-hosted solutions where I can, and just do without when I can't. It does make me a little sad that I can't get some of these cool "living in the future"-type devices, but I'd be sadder to have my home festooned with manufacturer-controlled surveillance and advertising delivery devices.
I wish there was a way to convince the average non-technical person of the merits of owner control. Given the enthusiastic responses in favor of allowing device manufacturers to mistreat owners I see from the Hacker News community, though, even convincing technical people is a lost cause. It feels like most people really want to be subjugated. It doesn't seem ratioinal.
I do recognize that the Hacker News community also includes some of the people who profit from subjugation of device owners. Their motivation seems rational (if not sociopathic).
I’m responsible for a bunch of IoT hardware, and every firmware spec I write includes a note on not using the DNS servers provided via DHCP. While sure there are companies explicitly doing this to avoid filtering, at least in my case it’s because a significant proportion of DHCP servers are configured to send DNS to your ISP, and ISP provided DNS is almost universally terrible. They’ll ignore TTLs, rewrite NXDOMAIN r…
What DNS do you hardcode? Google's? Or do you advice the use to set it up himself? I am very suspicious of the push for https and the like. I feel it is mainly about hiding the payload from me not any third party.
You might control the resolver on your personal computer (for now). You probably don't control it on your phone. You most likely won't control it on your embedded devices.
> some of these devices are using a sneaky tactic to bypass your PiHole entirely I don't think that it's malevolent on their part. Lots of ISP DNS are crappy. Hardcoding a reasonably reliable one saves them a lot of frustration and unnecessary technical support.
So if every single piece of hardware or software followed this one crazy trick the world would be better because some people at a tech company wouldn’t have to field as many support questions?
Margins are already razor thin in hardware, so yeah anything that can be done to reduce your support costs is welcomed.