Live data from Hacker News

Setting Up 1.1.1.1 for Families on a Pi-Hole

uglyduck.ca

31–40 of 82 posts

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#31
post #27

Earlier quoted context omitted.

Your router must support outbound NAT in order to force all connections on a specified port to a specified host. If your router doesn't have that feature, there's no way to do it.

You could double-NAT with a second router (apparently causes problems with some things like consoles, although I’ve never had a problem).

Double NATting is underrated. I have zero problems with it and I like the buffer zone (subnet) between the ISP's Gateway/Router and my home network. Should the ISP's device have a known Zero Day exploit then it won't affect my home's subnet. Then there's all the additional stuff that can be done on your own router and also use DoH to ensure that a compromised ISP-router can't rewrite your DNS queries. Plus your ISP's router won't be able to gather statistics about the devices in your home, in case it would do that. I don't trust ISP-provided devices at all.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#32
post #13

Earlier quoted context omitted.

I'd like use self-hosted dnscrypt-proxy, point pi-hole's upstream to it. Then dnscrypt-proxy will choose the servers that has lowest RTT and meet your requirement ( if DNSSEC, no log, family filter available) for you.

I even use it with blocklist and allowlist. No need for Pi-Hole, if you don't mind editing the lists directly.

Does it have regex support? That is the Pi-hole killer feature for me.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#33

why? arent we already using pi-hole for blocking all the stuff? that said, i have a query about a simple way to force all dns in a local network to pass through pi-hole. i only have access to the iSP router and pi-hole and cannot use third party router

MITM port 53 traffic

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#34

Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.

Parents have a responsibility to teach, guide, and educate their children to prepare them for adulthood. Today a vast amount of your "life" is online (much more than a decade ago). It only makes sense for parents to "parent" their children online.

> "Horrendously invasive"

Children do not have a right to privacy from their parents. Privacy (from parents) is a privileged that is earned and can be taken away. If you found your child off {insert worst thing you can think of} would you crack down on their privacy? Most parents would.

Parents also have the right to decide for themselves what really is "bad", and then try to raise their child according to those beliefs.

Don't confuse privacy from parents as privacy overall--children absolutely have a right to privacy from companies/3rd parties.

Simply because the internet doesn't physically harm you in an immediately noticeable way doesn't mean it's not dangerous or that harm isn't being done. It's good for parents to be aware of potential dangers (of which there are plenty) and to help their child navigate them.

Also, as other's have pointed out, the internet from decades ago is much different than the internet of today.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#36

I did test 1.1.1.1 and found it to be pretty slow on long tail domains (obviously everyone is caching popular ones). I bascially ran a 'dig' with multiple DNS providers and CloudFlare was slowest among the bunch for long-tail domains. Here are the details: https://twitter.com/vladquant/status/1428761979808669704 CloudFlare never responded to this tweet.

Interesting, but what are long tail domain?

Domains that have less frequent lookups so the chance of getting a cached response is lower.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#37

why? arent we already using pi-hole for blocking all the stuff? that said, i have a query about a simple way to force all dns in a local network to pass through pi-hole. i only have access to the iSP router and pi-hole and cannot use third party router

Pihole comes with a list of ads and trackers by default, but not with a maintained list of porn domains. There are more people working on getting trackers blacklisted than there are people scouring the web for new porn sites for free.

Pointing pihole at a porn blocker seems like a good combination of the best of both worlds to me.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#38
The one thing Cloudflare DNS is missing is providing something like NextDNS.

Choose your own filter lists (that are constantly updated), create multiple profiles to use according to the target device/location and enjoy as blocking at the DNS level. It’s not a complete match for something like uBlock Origin, but a lot of stuff still gets blocked with DNS filters.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#39

Earlier quoted context omitted.

My high school friend group lived on 4chan, and this was in the era of shock sites and the like. You grow out of it pretty quickly. Zero parenting experience here, but making something the "forbidden fruit" is probably how kids learn to change the DNS on their device. As far as I can remember, the only real-world consequence was someone applying Bengay where it should not be applied.

Point of clarification, was this before or after stormfront explicitly started using the site as a recruitment and training ground for neo-nazis? Because I also spent a fair bit of my middle and high-school time on 4chan, and can attest to the fact that the 4chan of 2007-2012 and the chansites of the present day are very different beasts.

That's true, I shouldn't speak to what it's like today as if it's the same when I don't actually know.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#40
post #34

Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.

Parents have a responsibility to teach, guide, and educate their children to prepare them for adulthood. Today a vast amount of your "life" is online (much more than a decade ago). It only makes sense for parents to "parent" their children online. > "Horrendously invasive" Children do not have a right to privacy from their parents. Privacy (from parents) is a privileged that is earned and can be taken away. If you fo…

> Children do not have a right to privacy from their parents.

They do everywhere outside the US, under article 16 of Unicef's convention on rights of the child. Of course this right is not absolute and many will say that the right to a child's safety comes before the right of a child's privacy, but children do inherently have a right to privacy. The convention does not exclude parents from this right for good reason.

There are parents who will demand their 17 year old child to hand over their private conversations, search history, you name it, and there are those that give 3 year olds unrestricted access to the internet. Neither extremes are healthy for children, but this "guidance" for the internet can last into children's late teens for certain parents.

The US signed the convention but did not ratify it, so you're correct that children don't have this right specifically in America. Legally speaking, the UN convention should ensure the right in all other recognised countries, though.

Post reply on HN