5 ms·
I've been using https://www.nextdns.io https://www.nextdns.io for the last month. It's PiHole as a Service.
by keiraarts 7y ago
I've been using https://www.nextdns.io https://www.nextdns.io for the last month.
It's PiHole as a Service.
- dvaun 7y ago+1 for nextdns. I've been using them since they were first posted to HN, and have had zero issues and enjoyed the ease of use. The iPhone app gives me the capability to block specific services while nextdns is in use (Facebook, Google, etc) and to easily disable it for the few moments I actually need to access certain platforms.
- fn 7y agoDo you use anything else in conjunction with it? Or NextDNS alone is enough? I ask because it seems simple enough that I can just install it really quickly on non-technical people's computers (when they ask me for help) without bothering to downloading a bunch of extensions on different browsers, updating stuff, etc, etc...
- ignoramous 7y agoNextdns is enough, but uBlockOrigin or uMatrix would be more effective for the web, along with DecentralEyes, CanvasBlocker, WebRTC Blocker, SmartReferrer, and other such extensions. Also, aggressive blocking can cause some websites and apps to break. dns.adguard.com (DoT) and https://dns.adguard.com/dns-query https://dns.adguard.com/dns-query (DoH) whilst not aggressive don't break as many websites and apps, and would remain free to use. Nextdns would cost you $1 a month if you need more than 500k queries once they're out of the beta stage.
- orangea 7y agoWow, what a creative use of IPv6 to allow a custom configuration without the use of DNS-over-HTTPS.
- ignoramous 7y agoDNS over HTTPS, DNS over TLS, and DNSCrypt are all abt preventing DNS manipulation attacks and encrypting the DNS traffic to the resolver (if not till the nameserver). Plain old DNS over UDP/53, IPv6 or not, can't be a substitute for that, afaik.
- Brajeshwar 7y agoWow! This looks awesome, promising. Just, wishing I saw this before I settled on Pi-Hole.
- jammygit 7y agoLooking at their site, it seems complicated to set up. What is the difference between IPv4, unbound, stubby, knot, and cloudfared - do you set one, or all of them? Do I want DNS over HTTPS, DNS over TLS, or both? Is it compatible with a VPN? For the trouble, it looks like it wouldn't be any harder to just set up your own Pi-Hole. Am I wrong?
- ignoramous 7y agoI understand where you come from, but I'd say they've made a good job of simplfying as much as they could at this early stage. Use DNS over HTTPS for: 1. Firefox. 2. Intra app on Android phones below version 9. 3. Clouflared on Linux. 4. Their official iOS app. Use DNS over TLS for: 1. Android 9 and above. 2. Knot or Stubby or unbound clients on Linux. IPv6 and IPv4 are for DHCP provided DNS: 1. With IPv4, you'd need to link your client-ip (public IP of your router) with your nextdns setup. 2. IPv6 doesn't require any such linked-ip acrobatics. Re: VPN: If you use DNS over HTTPS on Android or iOS, you won't be able to use a VPN, and that's because the DNS traffic is itself routed through a VPN and one can't chain VPNs on Android just yet. Other than that, VPN should work with rest of the setup mechanisms.
- jammygit 7y agoThanks!
- ignoramous 7y agoThe only problem I've encountered with nextdns is they went down effectively taking out internet and no one at home knowing how to mitigate it. Otherwise, a good value prop, provided you turn off their logging feature that captures client-ip among other metadata. Also, keep in mind that you could run Pi-Hole on a VPS and split-VPN only DNS traffic through it: https://docs.pi-hole.net/guides/vpn/only-dns-via-vpn/ https://docs.pi-hole.net/guides/vpn/only-dns-via-vpn/ DO charges $5 for 1TB traffic and a decent amt of compute, which ought to be enough for 500 or more (?) devices worth of DNS traffic.
- alibert 7y agoBeen testing Nextdns for several months now and it works almost great except a few thing: - EDNS is not working (the setting does nothing), I have tested it with Akamai CDN and they don't report any EDNS - The upstream DNS server used by Nextdns is not always the nearest to you, meaning some CDN will redirect you to some content cache server on another country. These two problems combined make downloading some content noticeably slower for me. And the weird part, I reached them via support and started troubleshooting with them and for no understandable reason they dropped the conversation and they do not respond to me now (??). I know it's beta with no warranty but still it doesn't look good. I'm back to pi-hole for my home network but I'm still using them on my iPhone although I'm looking to setup my own doh server + pi-hole and using the Adguard iOS doh client.