Live data from Hacker News

Setting Up 1.1.1.1 for Families on a Pi-Hole

uglyduck.ca

71–80 of 82 posts

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#71

Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.

Our networks have always been open and unmonitored for our children. We figured it would be better to train and guide them around the "search for pussy pictures" results than to let them grow up in a sheltered internet at home and get confronted with the "less desirable results" when connected to the open networks of friends & neighbours.

Well, good for you.

Are you telling us this for some reason other than to make yourself feel better about yourself? Because it comes off as sanctimonious and self-serving.

Different parents. Different families. Different cultures. They will all make different decisions. Your choice for your children is likely not the right choice for other people and their children. So I'm not sure what it is that you're trying to brag about.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#72

Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.

> I had unrestricted internet access as a child and turned out fine.

The statistical power of an n=1 study applied to a population many orders of magnitude larger is not very strong.

That aside, many, if not most children below a certain age lack the requisite ability to discern danger/non-danger with a fidelity that would satisfy their parents who have moral and legal responsibility in that domain. I admit there's a tension between privacy and the duty to protect.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#73
post #68

I still think this is a business that Cloudflare shouldn't be involved in. There are very legitimate reasons for parents to filter Internet content. But Cloudflare is in a unique position here, they have a brand as a company that cares about free speech, and specifically because of who they are, they really shouldn't be making determinations about what is and isn't inappropriate content for kids. When 1.1.1.1 for Fam…

I think it’s up to the network owner to decide what should be blocked or allowed in their network. 1.1.1.3 (or 2) is a tool in the tool chest. Some people may find it too aggressive and don’t need to implement it, some may find it too conservative and implement more. No tool will be perfect for everyone, and if you don’t find it hits the right balance you don’t have to use it. No one has to use it, and cloudflare can…

I agree that for an optional tool, Cloudflare can make any blocklist they like. People have a fundamental Right to Filter. I personally don't think it's consistent with Cloudflare's brand or stated purpose to go down this route, but that's just my opinion, people can have other opinions.

I do want to kind of question how egalitarian we are inside free speech communities about this stuff though in reality. I am fairly confident that if Cloudflare added hate speech to 1.1.1.3 or started adding misinformation to their filtering list, that is something that would show up on HN and see debate. I think a lot of people on this site wouldn't see that as a neutral act, I think a lot of people would be on here arguing that it was a dangerous value judgment, or at the very least a dangerous behavior for Cloudflare to normalize.

We all have the right to filter content, and we all have the right to choose which filter lists we'll use. But is that actually our philosophy? Would we collectively as a community be applying those same standards if Cloudflare started blocking Covid misinformation or conversion-therapy sites from 1.1.1.3? The way society debates filter lists can sometimes betray our collective ideas about what kinds of information needs more or less protection.

> or people were forced to use it

There's a separate conversation to be had here about the fact that children are forced to use filter lists. This is exactly why Cloudflare reacted so quickly to stop blocking sites like GLADD and why if it ever does offer the ability to choose custom categories, it's probably never going to offer an "LGBTQ+ information" category to block.

Cloudflare (to its credit) does at least recognize that child filters are often only semi-consensual and can be (and regularly are) abused at the network level.

That doesn't change the overall debate, it doesn't mean that making a filter list is always evil, communities still have a Right to Filter. But it is important to bring up, kids at schools don't get to choose whether or not the filters on those networks are too conservative or too liberal with what they block.

Kids (necessarily by virtue of being kids) do not have agency to decide what networks they're a part of. There are good reasons for that, but it still puts kids into a somewhat more vulnerable position, and it means there are more dangerous implications for network-wide filters than there are for user-controlled filters. This is also something that kind of gets glossed over in these debates sometimes.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#74

Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.

> I had unrestricted internet access as a child and turned out fine. The statistical power of an n=1 study applied to a population many orders of magnitude larger is not very strong. That aside, many, if not most children below a certain age lack the requisite ability to discern danger/non-danger with a fidelity that would satisfy their parents who have moral and legal responsibility in that domain. I admit there's a…

As humans, we can share our experiences on important human questions, such as what is an appropriate way to raise a child, without being told that a sample size of one is insufficient to found our opinions.

Also, with respect, you could also have made the point that my experience might not be the experience of everyone without dressing it up in statistical speak. I can assure you that I understand basic statistical principles.

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#75
post #27

Earlier quoted context omitted.

Your router must support outbound NAT in order to force all connections on a specified port to a specified host. If your router doesn't have that feature, there's no way to do it.

You could double-NAT with a second router (apparently causes problems with some things like consoles, although I’ve never had a problem).

can the pi zero as pi hole for example itself be the second router and pi hole at the same time?

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#76
post #45

Earlier quoted context omitted.

>Why aren't they just called infrequently used domains then? You could call them "infrequent" but "long-tail" is also a common description to convey a Power Law distribution: https://en.wikipedia.org/wiki/Long_tail I think in this case about DNS caching, "long tail" is better than "infrequent". In the wikipedia graph, some of the domain lookups in yellow may be "frequent" (absolute sense) but simultaneously but much…

DNS is essentially a cache. I've never once in my life heard of infrequently accessed cache items as "long-tail". This is definitely a dumb phrase that should be avoided.

I've never heard them referred to as anything else, so YMMV

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#79

I’d urge everyone to run a dns bench tool at home. Cloudflare isn’t always the right choice and for some ISPs with routing issues it can sometimes be a bad choice.

I found https://github.com/cleanbrowsing/dnsperftest/

to be really user friendy and easy to customize.

Here are results for my custom edited list of domains (first three are popular domains, rest are "long-tail" domains):

                     test1   test2   test3   test4   test5   test6   test7   test8   test9   Average 
   2001:558:feed::1  18 ms   18 ms   16 ms   30 ms   202 ms  377 ms  90 ms   87 ms   485 ms    147.00
   2001:558:feed::2  47 ms   31 ms   32 ms   154 ms  436 ms  343 ms  102 ms  76 ms   254 ms    163.88
   75.75.75.75       20 ms   16 ms   17 ms   78 ms   191 ms  293 ms  68 ms   75 ms   203 ms    106.77
   75.75.76.76       35 ms   33 ms   34 ms   149 ms  437 ms  283 ms  123 ms  102 ms  464 ms    184.44
   cloudflare        17 ms   19 ms   19 ms   103 ms  1135 ms 427 ms  69 ms   293 ms  191 ms    252.55
   level3            18 ms   17 ms   17 ms   45 ms   209 ms  231 ms  73 ms   49 ms   358 ms    113.00
   google            21 ms   17 ms   16 ms   37 ms   381 ms  124 ms  79 ms   28 ms   183 ms    98.44
   quad9             18 ms   19 ms   17 ms   42 ms   211 ms  127 ms  71 ms   73 ms   181 ms    84.33
   freenom           36 ms   49 ms   59 ms   88 ms   534 ms  342 ms  219 ms  82 ms   204 ms    179.22
   opendns           16 ms   19 ms   27 ms   23 ms   1514 ms 325 ms  85 ms   69 ms   488 ms    285.11
   norton            25 ms   27 ms   26 ms   134 ms  389 ms  243 ms  277 ms  273 ms  354 ms    194.22
   cleanbrowsing     22 ms   24 ms   27 ms   105 ms  533 ms  142 ms  70 ms   289 ms  199 ms    156.77
   yandex            192 ms  197 ms  191 ms  293 ms  378 ms  803 ms  287 ms  603 ms  232 ms    352.88
   adguard           84 ms   75 ms   74 ms   144 ms  240 ms  257 ms  72 ms   292 ms  170 ms    156.44
   neustar           18 ms   21 ms   16 ms   29 ms   389 ms  222 ms  276 ms  285 ms  315 ms    174.55
   comodo            65 ms   65 ms   82 ms   119 ms  458 ms  417 ms  236 ms  267 ms  290 ms    222.11

This was my setup for reference:

   DOMAINS2TEST="www.google.com amazon.com facebook.com mateja.prelovac.com enigma.rs hmdt.jp podravka.hr argentia.com.ar bildung.sachsen.de"

Re: Setting Up 1.1.1.1 for Families on a Pi-Hole

#80

Congratulations, you've just sent all of your legitimate DNS traffic to a tracker (the thing pi-hole is usually deployed to avoid). Remember that when a service is free, you are usually paying with your data.

Depends on whether you trust your ISP's DNS more than Cloudflare's. According to https://www.cloudflare.com/en-gb/learning/dns/what-is-1.1.1....:

> Unlike most DNS resolvers, 1.1.1.1 does not sell user data to advertisers.

Putting aside the question of whether they actually honour that commitment, has your ISP even published a similar statement to put their reputation on the line?

I think Cloudflare's commitment is plausible. They have a financial incentive to maintain their free DNS resolver's reputation and popularity, because they are selling points for their commercial authoritative DNS service; https://www.cloudflare.com/en-gb/dns/. Does your ISP have a similar financial incentive to behave?

"If it's free, you are the product" is not always true. Sometimes, if it's free, you are the marketing funnel.

Post reply on HN