3 ms·
There are instructions[1] for pointing your Pi-Hole directly to Cloudflare to forward DNS requests over DoH. You can use the same software to point at any other
by oskapt 7y ago
There are instructions[1] for pointing your Pi-Hole directly to Cloudflare to forward DNS requests over DoH. You can use the same software to point at any other DoH resolver, and you can disable (or alter the endpoint for) the DoH resolvers in Firefox and Chrome.
In July of this year my ISP (Entel Chile) started blocking all ICMP and DNS to non-Entel resolvers. They will not respond to tickets requesting an explanation or confirmation - DNS and ICMP just went dark. In response, I set up DoH on my Pi-Hole with the instructions above.
I don't trust Cloudflare, so a couple weeks ago I started modifying the tools from doh-proxy [2] to run in a container [3]. I have this running in three locations under my control, in networks that I trust (or at least that I trust more than Cloudflare), and in one location I run a proxy that uses Nginx to load-balance requests across the multiple locations.
I made two videos that show how you can set this up, first about the proxy [4] and how to run a stub DNS-to-DoH forwarder in Docker on your local machine if you don't control the network DNS server, and then about how to set up your own private DoH resolvers in Kubernetes (using a $5 VPS and running k3s) [5].
These solutions, while more technical than what my mom can put together, will not only use systems that you control, but depending on how you set it up, will encrypt all DNS traffic from your machine. Encrypting browser traffic is good for the masses, but it only solves a small part of the problem.
Even if you only use the proxy, you can forward to public DoH resolvers that include parental filters, adblocking, and other benefits. If you don't have a Pi-Hole or can't run one, you can get the same benefits with a service like NextDNS [6], who have a generous free tier.
The next step is to configure the resolver to support auth, so that it's not all just hanging out on the Internet like it is at the moment.
For those who are asking about malware and if DoH makes it easier - consider that this is an HTTPS request. All any malware has to do (and already does) is bypass your system's DNS configuration and make the HTTPS request for DNS resolution of C2 systems directly. Whether or not you have DoH active on your system for other requests is irrelevant.
[1]: https://docs.pi-hole.net/guides/dns-over-https/ https://docs.pi-hole.net/guides/dns-over-https/
[2]: https://github.com/facebookexperimental/doh-proxy https://github.com/facebookexperimental/doh-proxy
[3]: https://hub.docker.com/r/monachus/doh-tools https://hub.docker.com/r/monachus/doh-tools
[4]: https://youtu.be/1RTHCieZqls https://youtu.be/1RTHCieZqls
[5]: https://youtu.be/Z-_SpFWloQo https://youtu.be/Z-_SpFWloQo
[6]: https://nextdns.io https://nextdns.io
Edit: Link formatting