3 ms·
There's no extra hop? Do you carry the pihole around with you? Do you have a firewall running on your phone to block or redirect DNS requests? Since hardcoding
by Dahoon 6y ago
There's no extra hop? Do you carry the pihole around with you?
Do you have a firewall running on your phone to block or redirect DNS requests? Since hardcoding and bypassing the one in network settings is extremely easy and done by default by even some Google apps. DNS leaking VPN is trivial.
What logs are you talking about? Blokada can use the same upstream DNS as your pihole so the logs are exactly the same if any exists.
Without a firewall and a VPN (both on the phone) you are not secure. With a VPN and a custom DNS service with blocklists you have an identical setup as one who uses Blokada, but without an external service.
- kd913 6y ago>Do you carry the pihole around with you? No I leave my pihole at home? >Do you have a firewall running on your phone to block or redirect DNS requests? Since hardcoding and bypassing the one in network settings is extremely easy and done by default by even some Google apps. DNS leaking VPN is trivial. I assume wireguard's DNS field sets/redirects all DNS traffic through the VPN. If it ignores that setting, then Android's VPN design itself is broken. Switching to blokada won't fix this problem either. Either way, Android's Firewall/Network aspects don't give me enough control here. But I can see enough hits on my pihole to have some reasonable confidence. >What logs are you talking about? Blokada can use the same upstream DNS as your pihole so the logs are exactly the same if any exists. I don't have to trust the owners of blokada aren't keeping logs? Why would I need to trust them when I can use my pihole which I know doesn't keep logs? You are offering no advantages here compared to using my setup. >Without a firewall and a VPN (both on the phone) you are not secure. Well there is no competent firewall on the phone without root. Yes there is a VPN on both and it seems to work. >With a VPN and a custom DNS service with blocklists you have an identical setup as one who uses Blokada, but without an external service. Yes, I have an identical setup that I run myself without trusting some random owner of blokada. It runs externally just fine using my home network.