4 ms·
Why would you tunnel your DNS requests when you can just switch DNS on the phone to a filtering one and also use blocklists, IE. with Blokada? Unless you route
by Dahoon 6y ago
Why would you tunnel your DNS requests when you can just switch DNS on the phone to a filtering one and also use blocklists, IE. with Blokada? Unless you route everything, not only default DNS, through the VPN, any app can just hardcode its own DNS ip and if you route everything through the VPN Blokada will do exactly the same but without an extra hop. Sounds terribly complicated for something that gives less security and privacy. Mind you that is coming from someone who runs 3 Piholes on a homelab.
- kd913 6y agoYou make no sense. It's less secure and likely more privacy problems trusting a service with Blokada compared with my own pihole. My own pihole is accessible wherever I want, I know who has the logs for the DNS requests performed by my pihole which is done over DNS over HTTPS. The DNS requests are made securely through wireguard and just those requests. There is no extra hop?
- Dahoon 6y agoThere's no extra hop? Do you carry the pihole around with you? Do you have a firewall running on your phone to block or redirect DNS requests? Since hardcoding and bypassing the one in network settings is extremely easy and done by default by even some Google apps. DNS leaking VPN is trivial. What logs are you talking about? Blokada can use the same upstream DNS as your pihole so the logs are exactly the same if any exists. Without a firewall and a VPN (both on the phone) you are not secure. With a VPN and a custom DNS service with blocklists you have an identical setup as one who uses Blokada, but without an external service.
- kd913 6y ago>Do you carry the pihole around with you? No I leave my pihole at home? >Do you have a firewall running on your phone to block or redirect DNS requests? Since hardcoding and bypassing the one in network settings is extremely easy and done by default by even some Google apps. DNS leaking VPN is trivial. I assume wireguard's DNS field sets/redirects all DNS traffic through the VPN. If it ignores that setting, then Android's VPN design itself is broken. Switching to blokada won't fix this problem either. Either way, Android's Firewall/Network aspects don't give me enough control here. But I can see enough hits on my pihole to have some reasonable confidence. >What logs are you talking about? Blokada can use the same upstream DNS as your pihole so the logs are exactly the same if any exists. I don't have to trust the owners of blokada aren't keeping logs? Why would I need to trust them when I can use my pihole which I know doesn't keep logs? You are offering no advantages here compared to using my setup. >Without a firewall and a VPN (both on the phone) you are not secure. Well there is no competent firewall on the phone without root. Yes there is a VPN on both and it seems to work. >With a VPN and a custom DNS service with blocklists you have an identical setup as one who uses Blokada, but without an external service. Yes, I have an identical setup that I run myself without trusting some random owner of blokada. It runs externally just fine using my home network.