3 ms·
Actually no. By blocking 53 at your router to anything except your pihole, even a hard-coded IP like 8888 is blocked.
by asix66 4y ago
Actually no. By blocking 53 at your router to anything except your pihole, even a hard-coded IP like 8888 is blocked.
- cgriswald 4y agoYou'd have to do packet inspection. Otherwise a hostile hardware manufacturer could just run their DNS on a non-standard port.
- vladvasiliu 4y agoI guess if the relationship we have with our devices is full-on adversarial and yet still need them, they should be put on a dedicated subnet with a default deny rule in place. I guess, at this point, the other commenter's solution of "just stop using those things" may be the best.
- cgriswald 4y agoEven a dedicated subnet won't be enough, because these devices could be made to connect to any open wifi until they can phone home or even use the cell network, without the user even knowing about it. > I guess, at this point, the other commenter's solution of "just stop using those things" may be the best. Yeah. Assuming this doesn't change, this is the end result for me, at least.
- asix66 4y agoPerhaps, but blocking 53 is better than not, IMHO. I've seen devices fall back once blocked to a hard-coded dns, so it works today. DoH is another that devices will eventually employ, so that's another whack-a-mole situation.