28 ms·
My Chromecast Ultra would not start until I began answering 8.8.8.8
- reneberlin 8y agoNo more wonders?!
- crankylinuxuser 8y agoFor those running Linux machines for networking.. sudo iptables -t nat -I OUTPUT --dst 8.8.8.8 -p tcp --dport 53 -j REDIRECT --to-ports 53 sudo iptables -t nat -I OUTPUT --dst 8.8.4.4 -p tcp --dport 53 -j REDIRECT --to-ports 53 sudo iptables -t nat -I OUTPUT --dst 8.8.8.8 -p udp --dport 53 -j REDIRECT --to-ports 53 sudo iptables -t nat -I OUTPUT --dst 8.8.4.4 -p udp --dport 53 -j REDIRECT --to-ports 53 What that does, is catches requests coming in from the network going to Google's DNS, and redirects them to that local machine's port 53 (be it tcp or udp). Its an ugly hack, but things like PiHoles can reliably do this with little to no extra load, and keep the google spy engine off your tracks. But then we'll have to discuss using a chrome..
- Zecar 8y agoThis is really shady of Google to do, and the fact that they think that it's acceptable just shows how far we've come. "Don't be evil" apparently means "spy on people, censor based on politics, help dirtbags stuck in the 12th century treat women as property, and assist totalitarian regimes to stay in power and censor their populace". Google is literally cartoonishly evil at this point. That slogan of theirs is an absolute joke.
- givinguflac 8y agoOh they know, it’s why they got rid of it and it lives on as a sub note in employee guidelines. Because no one reads those.
- gsich 8y agoShitty device then. Or is there a legitimate usecase for such behaviour?
- dastx 8y ago> Or is there a legitimate usecase for such behaviour? Yes, to track you better.
- fixermark 8y agoOr to speed up the Internet experience. https://googleblog.blogspot.com/2009/12/introducing-google-public-dns.html https://googleblog.blogspot.com/2009/12/introducing-google-p...
- mthoms 8y agoInteresting then, that they chose to do this instead of giving monetary and technical support to the already established opendns.org Kind of like they started Knol to compete directly with Wikipedia.
- vatueil 8y agoDespite what the name may suggest, OpenDNS has always been a for-profit company, and they used to serve ads in the same way ISPs have been criticized for. Offering an alternative to OpenDNS was a good choice.
- mthoms 8y agoAh yes, you're right. It definitely seemed like they attempted to portray themselves as some kind of non-profit if memory serves.
- Rebelgecko 8y agoThere's so much latency already with the chromecast. how much difference does a few tens of milliseconds make?
- gsich 8y agoNot on a Chromecast. And not with every DNS. And no time difference is shown in the blogpost.
- leowinterde 8y agoVery questionable, as fallback possibly ok but not forced. Is it the same with home mini devices?
- dastx 8y agoI've confirmed that this is the case a while ago. Google Home, Google Home Mini. Netflix seems to do this as well with their apps.
- dastx 8y agoI posted this a while ago on the /r/pihole subreddit. Since my router is a bit more restricted, I ended up blocking Google's DNS as they've been doing this in other devices and software as well. It seems that they only add one of the dns servers and fallback onto the DNS server provider by DHCP. My pihole number of queries suddenly jumped up after I blocked those IPs.
- josteink 8y agoExpect more of this once “DNS over HTTPS” takes hold. Nothing Google makes will ever respect your DHCP-server or local network settings ever again.
- silon42 8y agoI guess we'll have to block protocols where DPI doesn't work.
- JohnFen 8y ago> Expect more of this once “DNS over HTTPS” takes hold. I do. DNS-over-HTTPS is why I've modified my network so I can MITM all HTTPS connections.
- josteink 8y agoSounds interesting. Do you have a write up about creating such a setup?
- JohnFen 8y agoNo, I don't, but it's conceptually pretty easy (the devil is always in the details). I'm sure you could find something on the net describing this better. What I've done is, first, to block the HTTPS port from going anywhere except to my proxy. If you want to use HTTPS in my network, you have to install my cert. That cert is used to negotiate the HTTPS connection to the proxy. The proxy then has access to the plain-text data stream. If that data stream is a DNS request, then it's diverted to a DNS-over-HTTPS server that I run (which uses my local DNS server to resolve the request). Otherwise, the proxy just transfers the data to and from the destination site using an HTTPS connection from the proxy to the destination.
- b1r6 8y agoThis is giving me some good ideas for my homelab... Thank you!
- 8y ago
- anilakar 8y agoIn case the name of the original poster does not ring a bell: https://en.wikipedia.org/wiki/Paul_Vixie https://en.wikipedia.org/wiki/Paul_Vixie
- paulddraper 8y agoCo-designer of DNS and member of the Internet Hall of Fame
- jasonjayr 8y agoI agree with the shadiness of this, but just to play devil's advocate here, is this to work around shitty ISP's that play games with DNS? Residential ISPs have not exactly been good faith actors in this game ...
- megous 8y agoYes, but how does it help hardcoding one IP address that ISPs can simply route to their own DNS server?
- tialaramex 8y agoToday the ISP could, with a bunch of effort, re-route the traffic, though I haven't seen any evidence that any of them do that. So it helps materially because for today it works. Tomorrow these devices will do DPRIV, probably DNS over HTTPS, and so the ISP won't be different from any other man-in-the-middle, unable to meddle with the contents of protected traffic.
- oarsinsync 8y ago> Today the ISP could, with a bunch of effort, re-route the traffic Injecting a route into your IGP is pretty trivial, any ISP with an engineer with more than 6 month's experience could manage this. > though I haven't seen any evidence that any of them do that Unless you've actually looked, and performed pcap analysis of what your dns request/response looks like to try and determine if your ISP is intercepting, you can't be sure. That said, several ISPs used to do this quite transparently (pun not intended) in the early 2000s, to return advertising pages whenever a DNS query failed. Some of them would do this on their own DNS servers (that were the default pushed to your CPE, which was then the default for your network), some of them would actually hijack anything going to udp/53. This used to be prevalent for a while. Then again, who's making more money monetising your activity? Your ISP or Google? Given that your ISP can already see every IP you visit and how much traffic you exchange with that counterparty, who would you rather protect your DNS requests from? Them or Google?
- richardwhiuk 8y agoI've seen this been done before, and IME it's reasonable behavior. I've seen so many instances of computers configured with DNS servers which are extremely slow, or provide garbage results, that adding a known good DNS server to the list, and then parallel resolving across all of them is a perfectly legitimate thing to do.
- zamazingo 8y agoUnless you want your own dns server used at all times.
- shawnz 8y agoBut why would you care about that? You're already connecting to Google's service, YouTube, so what does it change to use Google's DNS to resolve it? What is the circumstance where you'd care about not using Google's DNS but then connect to a Google service anyway? If Chromecasts allowed arbitrary web browsing, I would maybe see your point -- but they don't.
- sofaofthedamned 8y agoNot just Google - when you cast you handoff a URL to the CC to stream from - this could be from Netflix, or anywhere really. 8.8.8.8 as a brute-force backup I can understand, but by default it should be taking the network DHCP settings.
- fixermark 8y agoThat default, sadly, would basically guarantee the thing doesn't work for all too many users. And as a consumer electronics product (especially in the sub-$50 price-range), the market-smart thing to do is configure the defaults to work in the saddle-point of worst-case and common scenario (i.e. badly-configured local router talking to a standards-hostile ISP's DHCP configurations).
- 8y ago
- scrollaway 8y agoI'm always shocked at how easy it is for people to fall into the "Google is evil!!1" trap on such trivial stuff (and funnily enough, much more serious privacy issues related to Google are ignored/downvoted). Hardcoded DNS servers are common. Extremely common in a bunch of IOT devices, given how broken some ISPs are. This is a non-story and the only reason it's being upvoted is because Google is doing it, and they also control the DNS server. You know what would be an actual story though? If Google used Google DNS to spy on people. If anyone has concrete evidence that they're doing that, that is a big fucking deal. Not some email about a google-complaint-of-the-week. Edit: To be clear I'd agree that in a high quality product there needs to be a way to change the DNS servers. Then again, this is a $30 device to hook up TVs, and I've seen $200 routers lacking that ability. ---- Edit 2, elaborating on the above: You make a cheap device that will likely end up in millions of homes and your #1 support issue is "It doesn't work [because my ISP is terrible therefore my network configuration is shit]!". What do you do? Do you tell your consumers to suck it up and talk to their ISP? Or do you… hardcode a DNS server that you at least know will work? "Issues" like this one are non-issues and distract from the myriad of very real privacy issues coming out of Google. Yes, this should be configurable at the very least… then again, Google products aren't exactly known for their wonderful configurability.
- anilakar 8y agoIt's being upvoted because the issue was raised by none other than the father of DNS.
- scrollaway 8y agoGiven the ratio of people who upvote stories based on their title without clicking through, I highly doubt that.
- dang 8y agoWe don't know what that ratio is, as we don't track it, and I'm skeptical that anyone does.
- koolba 8y agoThis is pretty crappy and is the type of thing that would prevent you from a bunch of purely local use cases like pointing it at your local media server. Is this the Paul Vixie?
- ct0 8y agohttps://en.wikipedia.org/wiki/Paul_Vixie https://en.wikipedia.org/wiki/Paul_Vixie
- fixermark 8y agoI don't think it prevents streaming from a local media server, as that use-case is already supported. https://allaboutchromecast.com/chromecast-how-to-guide/comparison-of-5-methods-for-streaming-local-media-files-to-chromecast/ https://allaboutchromecast.com/chromecast-how-to-guide/compa...
- cotillion 8y agoJust the fact that you can't cast your own local content when the mothership is down makes me want to throw out all cast devices. Ignoring DNS servers seems like a very minor issue.
- clanrebornsx 8y agoWhy not use ckoudflare DNS. Google DNS is used for data mining... that's how Google crawls sites which are being requested. Google doesn't crawl whole web yet. Google also checks what site is doing how much traffic based on the DNS requests it figured out the traffic it gets and then ranks it appropriately for the search term making fake SEO ranking much harder.
- fixermark 8y agoThis guy sure is angry that his consumer electronics device is architected to be maximally convenient to set-up and use for the common user. He may want to consider an alternative product. Or use his 1337 hacker skills to modify his already-customized local routing configuration to just do the thing this consumer electronics device is assuming is standard (i.e. accessing services by IP on the Internet) by telling his network to proxy 8.8.8.8 to some other IP he designates.
- bobthedino 8y agoNot sure what you meant by "1337 hacker skills" (sounds sarcastic to me) but the guy in question helped create the Domain Name System!
- fixermark 8y agoI know, and yes, it was intended to be sarcastic. ;) He of all people should understand that the practical implementation of DNS and DHCP has become so broken by bad-acting ISPs that consumer electronics devices end up side-stepping the spec entirely so the thing works for the common consumer user.
- bobthedino 8y agoFair enough!
- chewz 8y agoSet DNS to Google and do dig +short TXT whoami.ds.akahelp.net Then set to other DNS provider and do the same You will see that Google DNS is delivering ECS which helps with directing traffic to nearest CDN. I have quite secure DNS setup but still forward some queries to Google DNS (HBO, Spotify, etc.) just to take advantage of using ECS.
- kop316 8y agoWhat I ended up doing to ensure this for any of the devices I have is use pfSense to force all DNS queries to go to my DNS server: https://docs.netgate.com/pfsense/en/latest/dns/blocking-dns-queries-to-external-resolvers.html https://docs.netgate.com/pfsense/en/latest/dns/blocking-dns-...
- 1over137 8y agoThis may be helpful too: https://docs.netgate.com/pfsense/en/latest/dns/redirecting-all-dns-requests-to-pfsense.html https://docs.netgate.com/pfsense/en/latest/dns/redirecting-a...
- deleted 8y ago[deleted]
- jdc0589 8y agoouch. I've got a free 4k Apple TV on the way I was planning on selling, but I may sub it in for my old Chromecast.... No way Im turning pihole off, and Im not gonna get a legit router setup to reroute 8.8.8.8.....
- ctime 8y agoIts not just this device, its others like the Google Home. Why? Because ISPs and home networks are awful a non-trivial amount of time. It also gives leverage to Evil ISPs to hold Google ransom for the DNS queries needed to make the thing work propertly. I dont think the average person knows or cares how fragile the internet actually is (unless, of course, you happen to live in China, which activiely manipulates and breaks DNS routinely for glorious reasons)
- bubblethink 8y agoThis is not necessarily to force ads, although that is a good side benefit. It's more to force geoblocking of content which smartdns operators circumvent. chromecast is afterall is a consumption device. If you stop consuming things you are fed, what are you ?
- deleted 8y ago[deleted]
- moonbug 8y agogrumpy old man yells at cloud.
- deagle50 8y agoDNAT 8.8.8.8:53 back to your own DNS server.
- brandeded 8y agoCame here to say exactly this. Why even make a fuss about it? Bro, do you even NAT? The argument is Google can record what you're sending your Chromecast. Well, (sorry for the crudeness) no shit... You're using Google hardware. If you're going to act like the DoD and not use Huawei switches, then don't use Huawei switches. If you so choose, you must look at Google as malevolent as the US DoD would see an attacking nation state, and actively do things about it (like not buy their hardware). Otherwise, shut yo trap.
- mthoms 8y agoCool, I'll be sure to tell my mother-in-law that if she's concerned about her privacy, she just needs to use NAT "bro".
- growse 8y agoTell her that if she's worried about Google spying on her, it's probably best not buy a Google-made device with Google-owned software on it transmitting usage data back to Google.
- mthoms 8y agoThis may be fair for "free" service like search. It gets way more complicated when the consumer is (a) paying for the device, (b) paying for the content they consume and (c) paying for the bandwidth it uses. All I have to do now is explain to my mother-in-law that she hasn't paid "enough". I'm sure she'll totally understand.
- deagle50 8y agoThis is what I've been telling my friends and family after I gave up trying to improve their network setup. At some point you have to take a stand and stop trying to have it both ways.
- hannob 8y agoGiven that ISPs like to play with traffic and have been using censoring DNS servers again and again I can't blame Google for taking away one piece of potentially failing networking infrastructure and using their own. It's not nice, but it's not Google who started this.
- ClashTheBunny 8y agoWhat happens when all DNS but the ISP's is blocked? I've been in many a corporate and cheapo Internet situation like this.
- joshstrange 8y agoYou are missing the point, it's not that they first try 8.8.8.8 then falling back to ISP/defaults, they are requiring 8.8.8.8 for DNS which is BS.
- hannob 8y agoIf they would fallback to the ISP's DNS server they'd encourage the ISP to block access to their DNS, which arguably would be even worse.
- mthoms 8y agoHonest question: is that even legal?
- CobrastanJorji 8y agoIn the US? Oh man, it's even worse than that. ISPs can probably legally choose to block whatever, including editorially blocking content they find offensive. Your ISP could legally choose to just start blocking port 443 because they want to make sure you're not looking at anything inappropriate. Comcast will straight up mutate HTML content sometimes to insert their own JavaScript: https://news.ycombinator.com/item?id=15890551 https://news.ycombinator.com/item?id=15890551
- AdmiralAsshat 8y agoKnowing who he is, my takeaway should be, "Wow! An Internet Hall of Famer weighing in against a Google product!" But my actual takeaway is, "Legends of the CS world write informal, pithy rants to Google just like the rest of us mortals."
- jchw 8y agoI find the responses on the mailing list to be interesting. Nobody there seems terribly amused by this thread so far. >Are you looking for https://support.google.com/chromecast/contactflow https://support.google.com/chromecast/contactflow ? >And [wasting our time] as well. And to be fair, I would've expected a personal blog post rather than an IETF post. This is definitely quaint, though it gets the point across.
- slim 8y agoIETF should be concerned since one solution to this problem is to hijack the DNS. Namely 8.8.8.8
- justizin 8y agoRight, realistically what Vixie is saying is: This is a major vendor failing to comply with IETF standards and using their market dominance to undermine open standards and protocols.
- dragonwriter 8y ago> This is a major vendor failing to comply with IETF standards What IETF standard is violated by a device using a known DNS server rather than the one offered by DHCP?
- trumped 8y agowhy didn't you rant about it first, then, AdmiralAsshat? (if you are so good)
- jmull 8y agoPithy, drunken, one or the other.
- deleted 8y ago[deleted]
- alias_neo 8y agoIt's not new, and but limited to Chromecast Ultra, I detected this from several Android devices (phones) pre-Pie and configured my firewall to redirect those requests to my own DNS. Regardless of their reason, many of us don't want to use Google DNS and the just using their control over these devices to force people to 8.8.8.8/8.8.4.4. I haven't checked how Pie behaves yet but it provides an option in the UI to specify private DNS. Also, I found some time ago, and am not sure if it's still the case, but some of their first-party apps hard coded Google DNS, so seeing one at the system level was irrelevant.
- metalliqaz 8y agoGoogle's business is built on web services, and we know for a fact that ISP occasionally try to inject bullshit into their customers browsing sessions via all kinds of dirty tricks. Their DNS is also designed to be faster than typical DNS. I wouldn't be surprised if Google sees this as a way to ensure the proper function of their devices.
- alias_neo 8y agoI'm not arguing with that, but lots of us can and do run our own DNS for various reasons, it should respect that, or provide a power-user way to override the default DNS. By all means offer fall-backs to Google DNS if it's not behaving correctly, for the reason you mention. I've found it's also, quite poorly implemented, particular on CC Audios, I had an instance last year where my internet connection went down at my ISP, my DNS saw 10s of thousands of DNS queries per-device from each of my Chromecast Audio devices in the time I was out at work. It was almost 40k DNS queries in ~12 hours, per device. Almost everything else on my network behaved normally, but the Google devices just went mental spamming the network with insane numbers of impossible requests, back-offs are a thing, they should use them.
- freeopinion 8y agoDNAT
- unethical_ban 8y agoJared Mauch's response was pretty rude. I don't mind defaults, but I do not like the inability to change. I wonder if it was clearly documented as a device requirement that 8.8.8.8 was needed. All prerequisites of function should be in the Quick Start Guide of the tool in question. Furthermore, users aren't always in control of the firewall/ACL on their network. If I go to Jack's Organic Coffee for a meeting and they only allow 1.1.1.1 out for DNS, I can't use my cast device? That's screwy.
- roblabla 8y agoIt was rude because the DNSOP WG mailing list (to which this email was sent to) isn't a google support forum. https://datatracker.ietf.org/wg/dnsop/about/ https://datatracker.ietf.org/wg/dnsop/about/ outlines what the DNS WG is about. Ranting about how Google's devices are terrible isn't an appropriate use of this communication channel.
- Aiphie3E 8y agoI assume he does not want support. He wants to highlight a threat to DNS choice.
- belorn 8y agoThe threat is actually more at IANA than DNS. I would not be surprised if ISP supplied routers would start MITM quad ip DNS servers in order to retake the data and control. A lot of harm will happen if that became standard practice. DNSSEC do not protect against this.
- lukeschlather 8y agoWould that break DNSSEC?
- belorn 8y agoNo. DNSSEC makes sure that the record is correct as given by the authoritative DNS server. It does not specify or control who resolved the name and for whom.
- nemonemo 8y agoFrom this post, it is unclear whether the DNS given by DHCP should be 8.8.8.8, or the device only needs reachability to 8.8.8.8. I think if the latter is true, it seems acceptable, given the internet can be unpredictable, and Google network reachability would be correlated among services.
- izuchukwu 8y agoI could be misunderstanding, but if subsequent requests are to be made with the DNS provided by DHCP, reachability to 8.8.8.8 would only be helpful to disambgiuate what kind of network error is causing a failure to make network calls regularly. Otherwise, reachability would be best tested with, for example, a Google domain using the provided DNS.
- Fnoord 8y agoI have and use a Chromecast Ultra and redirect all traffic outward to port 53 to an internal DNS server which blocks ads and utilizes DNSSEC. I don't block 8.8.8.8 specifically though but it cannot be used by normal means as it would get redirected
- EastSmith 8y agoWe desperately need PrivacyFirst product reviews with 1 to 5 ratings, links to buy, reviews, etc. Someone please build it and put your referral links there - I will click on them all. Recently I wanted to buy home speakers and realized that all devices with top reviews need an app to function, and I need to agree to some privacy terms, etc. We need to have have old school products where I am giving you X bucks and you leave me alone.
- ajross 8y agoYeah. I know we'd all want to believe that the response and reaction here would be the same if it was pointed to 1.1.1.1, but... yeah, we know better. Everyone would point out that consumer ISPs server polluted data and that Cloudflare clearly provides better service, and relying on that instead of the local garbage is quite obviously a benefit to the device user. But this is Google, and people here have iPhones, so sharpen those pitchforks and light the torches. It's really getting out of control at this point.
- toast0 8y agoIt's not unreasonable to attempt to use DHCP provided DNS servers. It's not unreasonable to use fallback DNS servers when the DHCP provided servers don't work. It would be a bit strange, but maybe not altogether unreasonable to run a fully recursive DNS client with root.hints and what not. I guess you could argue over reasonableness of favoring the fallback DNS over DHCP. It's not reasonable to ignore DHCP when the fallback DNS doesn't work though. It doesn't matter what fallback DNS you're using.
- deleted 8y ago[deleted]
- Topgamer7 8y agoI think the difference is that the chromecast would not function without 8.8.8.8. Thus requiring you use googles services to use a google product. That is not cool.
- sowbug 8y agoIsn't using a company's product exactly when you'd expect a dependency on that company's service?
- CapacitorSet 8y agoIt's not a dependency that I expect of browsing devices. I expect to be able to use eg. a TV, a radio or an ebook reader entirely without relying on the vendor, save for technical support maybe.
- calibas 8y agoThis should bother people here more than it does. The last thing the Internet needs is even more dependence upon Google. They've made it quite clear through their actions that they're not supporters of a free and open Internet: https://theintercept.com/2018/09/14/google-china-prototype-links-searches-to-phone-numbers/ https://theintercept.com/2018/09/14/google-china-prototype-l... If people don't push back against these kinds of things, Google will continue to abuse their power. There shouldn't be an army of apologists here making excuses for them. As far as a solution goes, they can simply make 8.8.8.8 a fallback when something goes wrong. It's a disturbing trend to see them forcing things like this upon users.
- pexaizix 8y agoIt doesn't bother me because it's a Chromecast, an appliance I don't want or need. If I needed something similar, I could get it from other manufacturers.
- arbitrage 8y agoFirst they came for the appliances I don't want or need, because I don't use appliances I don't want or need. This has been discussed to death. Slippery slope, etc., etc.
- mrcarruthers 8y agoMy Roku does (almost) the same thing. It defaults to 8.8.8.8 to attempt to block dns proxies, but if you block 8.8.8.8 on your router, unlike the Chromecast, it will actually use the DNS server my router provides.
- nickspacek 8y agoI believe that this approach also used to work with the Chromecast.
- kissgyorgy 8y agoMy bigger issue with this kind of behavior (beside that I have the exact same issue with it) that I can't watch anything even from my local network when the internet is down from my ISP. Very frustrating.
- RickS 8y agoMore concerning to me was the fairly recent removal of non-phone-app setup. It used to be that a chromecast would display a 4 character code on screen, which could be used to activate it from the browser. Now, they require that it be managed with the google Home app, and have discontinued the method that allowed chromecast use without installing additional google software on your phone. This made for a really disheartening christmas experience, when I first assured my mother that no, we could skip this stuff with your phone, only to find out that no, she would indeed have to make that sacrifice. Especially frustrating is that my same devices, validated with the old method, continue to function just fine. Does anyone with more knowledge than I have know of a reason for this that isn't data-greedy or consumer-hostile? From my perspective, "Don't be evil" has been dead long enough that the bones are sunbleached.
- 05 8y agoThe obvious reason is that any local browser config pages cannot be SSL protected because the device can not provide a valid certificate for 192.168.0.33 or chromecast.local Phone app can use a custom TLS CA to make sure the stick was produced by Google and is not a rogue neighbor phishing for your WiFi password..
- djrogers 8y agoNo, that's not how it worked - you got a code on the screen you could use to activate the device with google from any browser - much like many many many TV apps use (visit foo.com/activate and enter code NNNN). You weren't browsing to any local devices...
- dragonwriter 8y ago> No, that's not how it worked Yes, it is; Chromecast activation has always used the Chromecast itself as the WiFi host; you have to do that to even set it up to use another network. > you got a code on the screen you could use to activate the device with google from any browser - much like many many many TV apps use (visit foo.com/activate and enter code NNNN). TV apps can do that because the TV device is already configured to connect to a network. And both the app and your browser can connect to the same remote server. Chromecast activation can't work that way, since it occurs as a necessary prerequisite to connecting the Chromecast to a network.
- optimuspaul 8y agoI don't understand, why does he have a google product if he doesn't want to support google?
- walrus01 8y agoSomething that's always highly amusing is when people who have no idea who Paul Vixie is try to school him about anything DNS related... Never fails to make me chuckle.
- sadris 8y agoJust DNAT 8.8.8.8 to your DNS server.
- hendersoon 8y agoI redirect all outbound DNS queries from my untrusted/IoT and guest VLANs to an internal caching DNS server for this reason. I use Pihole [1] which also blocks ads in mobile apps and such, very convenient. Providing a DNS server via DHCP is insufficient as many IoT devices ignore it for tracking purposes. Similar deal with blocking port 53 outbound, they just refuse to work. [1]: https://pi-hole.net/ https://pi-hole.net/
- ChuckMcM 8y agoGotta love Paul's approach. Amazing to see things that break when you run a black hole DNS server on your inside network. I have a Samsung TV that won't complete boot until it has verified there aren't any firmware updates at Samsung. I finally resorted to copying the http response traffic and having an a bit of code on my RasPi return it when the TV asks (it says "no new firmware for you"). Of course these sorts of tricks will fail when vendors get wise to them and start returning an encrypted time and date nonce in the response.
- mrweasel 8y agoThe extend to which modern appliances feel a need to be internet connected is getting ridicules. My TV isn't going to be internet connected, even if it's able to. It simply have no reason to. Smart TVs in particular should not be a thing. The TV manufactures have proven themself incapable of writing and maintaining software, so at this point they should accept defeat and just produce the TVs with enough HDMI connections.
- ChuckMcM 8y ago> My TV isn't going to be internet connected, even if it's able to. I admire your sentiment but recognize that on the current path that means at some point in the future this choice will mean "I don't have a TV." What is missed here, and alluded to in other comments, is that the costs for things are being subsidized by selling the digital exhaust they generate. Creating more exhaust means more margin, less (or even zero) exhaust means less margin. Since consumer electronics compete on price, a zero exhaust device will cost more and won't sell as well. So the market won't produce them. Further, the ability to convert a consumer device to one that generates zero exhaust will get targeted, and since there is no way to "win" that race, the final act will be a consumer device that refuses to operate if its ability to spew digital breadcrumbs is disrupted. Just like HP "all in one" printers will refuse to scan a document if they are low on ink. They don't need ink to scan, but the purpose of the printer is to create a recurring revenue stream for high margin ink, so all functions are in service to that purpose. Allowing utility that would mitigate the need to buy ink is unacceptable.
- imagiko 8y agoI'm a dumdum when it comes to understanding stuff about DNS. Why is this bad, and are there any good resources for understanding how these are used by companies to extract more information about our habits?
- pbhjpbhj 8y agoIf someone controls your DNS they can monitor and/or control your internet traffic flow. Like controlling your phone exchange, one can either watch who you connect to, or connect you to other phones regardless of the phones you try to connect to.
- kllrnohj 8y agoExcept in this case nobody is controlling your DNS, as Chromecast doesn't let you make arbitrary DNS requests via it. So Google/Chromecast only knows what DNS lookups Chromecast makes, which changes nothing with regards to privacy or anything else. It can't watch what you're doing, it can't snoop on your web traffic, etc...
- rasz 8y agoChrome is just as insistent on using 8.8.8.8. Took me >2 years of constant pestering to make Vivaldi finally patch some of it out. https://www.reddit.com/r/vivaldibrowser/comments/a23071/how_private_is_vivaldi/ebgz0zx/ https://www.reddit.com/r/vivaldibrowser/comments/a23071/how_...
- collsni 8y ago1to1 Nat your traffic that is what I did
- reneberlin 8y agotldr-shortcut: expectation doesn't "meat" crushed tech-stack. Maybe there is a wet-ware problem 2b solved. (It's friday night,guess - i'm too drunk to be xpected gentle conv.)
- zenmaster10665 8y agowut?
- llacb47 8y agoThis might explain why whenever I use a different DNS, some google subdomains refuse to connect.
- cfv 8y agoMy oven should not refuse to work if my gas pipes are not from the same maker. The ability to set up my own products to whatever config I like is not an extraordinary request. Especially when it's the default operating mode with an off brand product. Google should collectively be ashamed.
- chemmail 8y agoSO this guy is complaining that he is using a google product to use another google product and needs to use google in between to have that happen. Right.
- johnmarcus 8y agoWhy didn’t he just return the device if he doesn’t like the way the Google product used Google services to function?
- r3vrse 8y agoJust static route Google DNS back to your gateway. Works fine for me. As others have said though, who buys a Google device thinking it's not gonna talk to Google?
- homero 8y agoMy router enforces quad9 and my Chromecast is fine. How's that different? Maybe my router masquerades the dns port and answers vs blocking other dns outright?
- muppetman 8y agoI reject (not just drop, reject as in send back an ICMP message) 8.8.8.8 and 8.8.4.4 in my home network, and my Chromecast Ultra works just fine. I know it's talking to the PiHole too because I see it in my logs. So I don't believe the OP, even though it's the living legend that is PV.
- sasasassy 8y agoChromecast didn't even need a Google account a while back. Now (last few years) it forces it on you for no discernible reason. Supposedly now you can use their Google Home app to search for apps to install that work with Chromecast, which is already possible in the Play Store. The easy solution is to use an old version.
- accrual 8y agoI don't disagree that this is a Bad Thing. I like to use a BSD based router and a PF firewall. My solution: match in on $i inet proto udp from any to !($i) port {53 123} rdr-to ($i) "Any UDP packet destined for port 53 (DNS) or 123 (NTP) that is not the gateway ("$i"), redirect them to gateway ("$i"). The gateway has daemons listening and caching requests for performance. The client has no idea this is happening. It works great for me.