10 ms·
Is the Pi-Hole even reasonably effective these days? > Nearly 70% of smart TVs and 46% of game consoles were found to contain hardcoded DNS settings - allowing
by e2le 5y ago
Is the Pi-Hole even reasonably effective these days?
> Nearly 70% of smart TVs and 46% of game consoles were found to contain hardcoded DNS settings - allowing them to simply ignore your local network’s DNS server entirely.
https://labzilla.io/blog/force-dns-pihole https://labzilla.io/blog/force-dns-pihole
- jjulius 5y agoYes; PiHoles are used for far more than just blocking smart TVs. The difference between browsing the web at my house and browsing away from home is so stark that it's almost not worth browsing most sites if I'm not behind it.
- QuarterReptile 5y agoSo true. At about one week per year spent at a relative's home, I start to consider putting a pi-hole there, too.
- kstatz12 5y agoI did what i think is the logical extreme and put a pihole on my tailscale network and use that as my dns on any device connected to that network so i have it on the go
- QuarterReptile 5y agoOoh, I will be all over that if the fiber rollout in my neighborhood ever finishes.
- vlunkr 5y agoI run a simple VPN at my house alongside pinhole. You can block ads anywhere that way.
- axjmc 5y agoI do the same. The same pi runs a wireguard server.
- jjulius 5y agoI've been strongly considering it precisely because of this, just need to get around to setting it up.
- jrnichols 5y agothat is what I am connected to right now. it's amazing how much more lightweight the internet is in general with pi-hole/etc.
- Zizizizz 5y agoYep, took me about 5 minutes to set up with tailscale https://tailscale.com/kb/1114/pi-hole/ https://tailscale.com/kb/1114/pi-hole/ (wireguard)
- JohnTHaller 5y agoCurious why you're not using Firefox + uBlock Origin. It does CNAME lookups.
- dec0dedab0de 5y agoSounds like we also need a list of IPs to null route
- icecap12 5y agoThe workaround is already in use for ad hosting - serve all the content from one domain (or an IP) with services natted behind that, so if you block it, nothing works.
- matheusmoreira 5y agoThe ideal solution is custom clients for every service. Why use their proprietary software? We should make our own software we can use to connect to their servers. That way we can make it do whatever we want.
- hiptobecubic 5y agoYou two are talking about different problems.
- dec0dedab0de 5y agoIn that case we need to proxy, but only the wanted requests. Though in the case of a smart TV, you would want to block everything except for whichever streaming services you're subscribed to.
- brynx97 5y agoYou can create port forward firewall rules to redirect any outbound DNS port 53 traffic. This will not work for DNS over HTTPS, which is going to be increasingly common for IoT I'd imagine. edit: method for this on pfSense: https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.html https://docs.netgate.com/pfsense/en/latest/recipes/dns-redir...
- syshum 5y agoThen you have to contend with DNS over HTTP, Thanks Firefox and Google.... DNS over HTTP has got to be the most ill thought out "privacy" feature that has done more to HARM privacy then it could ever help
- walterbell 5y ago> the most ill thought out "privacy" feature Whose privacy? DoH helps to protect billions in revenue for the ad network that funds Chrome, Firefox, Safari and web standards. A better web will need a different revenue model. In the meantime, here's a maintained guide to blocking DoH with pfsense, https://github.com/jpgpi250/piholemanual/blob/master/doc/Block%20DOH%20with%20pfsense.pdf https://github.com/jpgpi250/piholemanual/blob/master/doc/Blo...
- eli 5y agoMany of the biggest ISPs in the US are actively monitoring DNS queries, collecting the data of which sites you visit, and packaging it for sale to ad networks and data brokers. DoH stops that.
- DistractionRect 5y agoIt really doesn't, as server name indication is sent in clear text. As encrypted SNI didnt take off, you dont actually get privacy benefits from DoH and friends, just security/mild inconvenience to censors.
- 5y ago
- simcop2387 5y agoI've setup firewall rules to redirect traffic from some devices to avoid that, but some are starting to use dns over https which is more difficult to deal with
- woodruffw 5y agoIt probably depends on your use patterns. I have a console and a TV in my apartment, but I spend much more time on personal computers than I do on either. My Pi-hole instance is still reasonably effective for that, and I'm sure I could (eventually) be motivated to do the workaround described in the post you linked.
- deleted 5y ago[deleted]
- SmellTheGlove 5y agoI block my TV’s MAC at the router. I use a roku for the streaming apps, which doesn’t seem to hardcode it’s DNS yet. But when it does you can just write some iptables rules. When they switch to dns over https, well I don’t know then haha.
- teeray 5y agoYou can DNAT those requests at the router over to a Pi-Hole, unless they’ve upgraded to DoH
- radikalerludwig 5y agopass in on $int_if proto { udp, tcp } from any to any port domain rdr-to [pihole_ip] port domain