Earlier quoted context omitted.
I think [1] is quite irrelevant to be honest. Blocking DNS isn't a destructive operation. I've been using pi-hole for years and I simply block everything and cherry-pick a few exceptions here and there when something breaks. I only had to really troubleshoot maybe 3-4 times in years, and half of that were related to the fact I worked for companies that had domains blocked.
It's destructive if you can't reach your remote devices anymore. See also jeff geerling's "It was DNS T-Shirt" https://www.redshirtjeff.com/shop/p/it-was-dns-shirt
Pi-hole v6
191–200 of 316 posts
Re: Pi-hole v6
#192Slightly off topic, but it annoys me that protonvpn does not allow split tunnel of DNS to an internal host. It calls this DNS leak protection, which is a good default. But I want to run my own DNS server and I know what I'm doing, and the Proton GUI won't let me.
Re: Pi-hole v6
#193Re: Pi-hole v6
#194Re: Pi-hole v6
#195I set up pi-hole recently after hearing about it for years. I was kind of surprised at a lack of really basic features (imo): There isn't any kind of "dry run" or "phantom" mode, where requests are not actually blocked, but appear marked in the log UI as "would be blocked". This is super important because I want to see all the things my home network is doing that would be blocked before I actually hit the big red but…
> For my "smart tv" which I begrudgingly have to allow on my network occasionally for software updates Why install software updates if you don’t use the “smart” features? Our smart tv has been banned from the internet for years.
Re: Pi-hole v6
#196Earlier quoted context omitted.
I hope that you at some point will understand that these are minorities among a huge population that you are talking about. It sounds like you think that every butcher, barber, dancer, teacher, software dev etc in China is just thinking of how they can hack the US. Guess what: that's the image propagated by propaganda and very far from the actual truth. If you don't trust people, study their code and make a formed op…
This seems like woefully naive virtue-signaling to me. I geo-block all traffic from Iran, N Korea, China and Russia specifically at my clients' firewalls because I have watched the logs and could clearly see IPs from each of these countries attempt connections to American businesses every minute of every day. Try to single out the offending IP and tomorrow it moves to another; you will spend the rest of your days add…
Re: Pi-hole v6
#197Earlier quoted context omitted.
it's more than that - an app running on your internal network is going to have way better latency than nextdns
However you can't use it on the phone while not at home (aside from using vpn/wireguard), but nextdns allows it. As for the latency - is it really noticeable?
Unbound, recommended for use with Pi-hole, can be configured to log this by enabling "log-replies" in unbound.conf⁽¹⁾ where the time to resolve will be logged in seconds.
⁽¹⁾ https://docs.pi-hole.net/guides/dns/unbound/ ⁽²⁾ https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound...
Re: Pi-hole v6
#198Earlier quoted context omitted.
Can’t you just use uBlock for this?
Pihole catches a lot of the trackers and crap coming out of my android tv. On my pc I see it as an extra line of defense after ublock.
Re: Pi-hole v6
#199I've been using AdGuard Home, which does pretty much the same thing, but is slightly better polished, with things like support for DoH and OSs other than Linux. https://github.com/AdguardTeam/AdGuardHome
I even run Adguard Home on my router that runs opnsense.
Been happy with my pihole for a few years, and this thread is full of new information for me.
Re: Pi-hole v6
#200Earlier quoted context omitted.
Is there an equivalent of DDWRT/OpenWRT but for TVs? Most often those are some embedded linux board running some Android fork, shouldn't there be some TV models on the market that are a good hardware/price deal with firmware that can be replaced? Even something that just permanently shows HDMI input with no popup overlays would be good, but AOSP + VLC/Jellyfin would be even nicer.
Would be fun if some could hack those os'es indeed. It could make a nice CrowdSupply project, except for the cheap distribution of the huge packages. Sounds not that hard though: Just get some nice 50" 4k smart tv's and remove all the junk. Cool features like DP daisy chain or something and one could have a nice project. But i'm guessing there is (too) much money to be made in user info and ads. :(