Live data from Hacker News

Pi-hole v6

pi-hole.net

191–200 of 316 posts

Re: Pi-hole v6

#191

Earlier quoted context omitted.

I think [1] is quite irrelevant to be honest. Blocking DNS isn't a destructive operation. I've been using pi-hole for years and I simply block everything and cherry-pick a few exceptions here and there when something breaks. I only had to really troubleshoot maybe 3-4 times in years, and half of that were related to the fact I worked for companies that had domains blocked.

It's destructive if you can't reach your remote devices anymore. See also jeff geerling's "It was DNS T-Shirt" https://www.redshirtjeff.com/shop/p/it-was-dns-shirt

The only times I have seen this happen is when the remote devices were communicating with something on blacklist (which should be concerning anyway, but also a quick fix if not) or doing something naughty like not using the DNS server broadcast by DHCP.

Re: Pi-hole v6

#192

Slightly off topic, but it annoys me that protonvpn does not allow split tunnel of DNS to an internal host. It calls this DNS leak protection, which is a good default. But I want to run my own DNS server and I know what I'm doing, and the Proton GUI won't let me.

The GUI app should have a custom DNS option:

https://protonvpn.com/support/custom-dns

Re: Pi-hole v6

#195
post #34

I set up pi-hole recently after hearing about it for years. I was kind of surprised at a lack of really basic features (imo): There isn't any kind of "dry run" or "phantom" mode, where requests are not actually blocked, but appear marked in the log UI as "would be blocked". This is super important because I want to see all the things my home network is doing that would be blocked before I actually hit the big red but…

> For my "smart tv" which I begrudgingly have to allow on my network occasionally for software updates Why install software updates if you don’t use the “smart” features? Our smart tv has been banned from the internet for years.

Same, my smart tv has never heard of the Internet.

Re: Pi-hole v6

#196

Earlier quoted context omitted.

I hope that you at some point will understand that these are minorities among a huge population that you are talking about. It sounds like you think that every butcher, barber, dancer, teacher, software dev etc in China is just thinking of how they can hack the US. Guess what: that's the image propagated by propaganda and very far from the actual truth. If you don't trust people, study their code and make a formed op…

This seems like woefully naive virtue-signaling to me. I geo-block all traffic from Iran, N Korea, China and Russia specifically at my clients' firewalls because I have watched the logs and could clearly see IPs from each of these countries attempt connections to American businesses every minute of every day. Try to single out the offending IP and tomorrow it moves to another; you will spend the rest of your days add…

i used to do similar on gaming clans' forums; for local rationalized fps we didnt want folks with 300+ ping and country blocking was pretty easy (and folks on the forums were either spamming us with porn or trying to become a member). though since it was forums based i did allow GETs but restricted POSTs ect vs straight up 0 access

Re: Pi-hole v6

#197

Earlier quoted context omitted.

it's more than that - an app running on your internal network is going to have way better latency than nextdns

However you can't use it on the phone while not at home (aside from using vpn/wireguard), but nextdns allows it. As for the latency - is it really noticeable?

Latency isn't the important measurement — it's the actual time to resolve. This will be significantly longer than the ping latency.

Unbound, recommended for use with Pi-hole, can be configured to log this by enabling "log-replies" in unbound.conf⁽¹⁾ where the time to resolve will be logged in seconds.

⁽¹⁾ https://docs.pi-hole.net/guides/dns/unbound/ ⁽²⁾ https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound...

Re: Pi-hole v6

#198

Earlier quoted context omitted.

Can’t you just use uBlock for this?

Pihole catches a lot of the trackers and crap coming out of my android tv. On my pc I see it as an extra line of defense after ublock.

Hulu stopped working properly on my Shield after using Pi-Hole, so I guess it was working?

Re: Pi-hole v6

#199
post #22

I've been using AdGuard Home, which does pretty much the same thing, but is slightly better polished, with things like support for DoH and OSs other than Linux. https://github.com/AdguardTeam/AdGuardHome

I even run Adguard Home on my router that runs opnsense.

What routers are compatible with opnsense? Or does it need a full-blown server/container?

Been happy with my pihole for a few years, and this thread is full of new information for me.

Re: Pi-hole v6

#200

Earlier quoted context omitted.

Is there an equivalent of DDWRT/OpenWRT but for TVs? Most often those are some embedded linux board running some Android fork, shouldn't there be some TV models on the market that are a good hardware/price deal with firmware that can be replaced? Even something that just permanently shows HDMI input with no popup overlays would be good, but AOSP + VLC/Jellyfin would be even nicer.

Would be fun if some could hack those os'es indeed. It could make a nice CrowdSupply project, except for the cheap distribution of the huge packages. Sounds not that hard though: Just get some nice 50" 4k smart tv's and remove all the junk. Cool features like DP daisy chain or something and one could have a nice project. But i'm guessing there is (too) much money to be made in user info and ads. :(

Top tip: some smart TVs will turn into perfectly serviceable dumb TVs if you reject their on-screen software license agreement/privacy disclaimer.
Post reply on HN