4 ms·
I just block all outbound port 53 traffic, any device or app that doesn't honor my DHCP-provided DNS resolver can suck it. Looking at you, Chromecast that trie
by addingnumbers 5y ago
I just block all outbound port 53 traffic, any device or app that doesn't honor my DHCP-provided DNS resolver can suck it.
Looking at you, Chromecast that tries 8.8.8.8 40 times an hour even though you know perfectly damn well that 10.10.10.1 is working
- robocat 5y agoThe DNS provided by many ISPs is not to be trusted, as per this thread, so how else can your Chromecast act to find a trustworthy DNS? And with newer decides that use DoH, you can no longer prevent devices from contacting their own DNS provider without totally firewalling them (or perhaps using some IP blacklist or whitelist, if available?) https://en.wikipedia.org/wiki/DNS_over_HTTPS https://en.wikipedia.org/wiki/DNS_over_HTTPS
- addingnumbers 5y agoWhen I said blocking all outbound 53 I meant no exceptions, my local forwarder already uses DoH to an outside resolver. Everything that I don't have complete visibility into the network stack of goes on a VLAN that does not forward traffic to the internet, it advertises a proxy via WPAD and DHCP option 252. I have a whitelist of hostnames that each device is allowed to make CONNECT requests to, so far there is only one. If it's not a plain unencrypted HTTP request to my proxy, or a CONNECT request involving a server/device pair I've decided to trust, it's not going anywhere. This breaks a lot of things that I would just as soon rather do without. I can't change my universal remote hub settings from the vendor portal, boo-hoo. I can't view my cameras from the hardened VLAN or from the internet (unless I VPN in first since the only copy of the recordings is on my local NAS)... good.