3 ms·
Are you referring to iCloud Private Relay? If so that's expected behavior for with any DNS based ad blocker. Turning on the relay proxies your connection and yo
by pseufaux 3y ago
Are you referring to iCloud Private Relay? If so that's expected behavior for with any DNS based ad blocker. Turning on the relay proxies your connection and your local network's DNS server will not be used. Doesn't matter if it's PiHole, NextDNS, or AdGaurd.
- hbcondo714 3y agoThanks, I did not think of that but iCloud Private Relay requires an iCloud+ subscription[1] which I do not have. I'm referring to the "Limit IP Address Tracking" option[2] in Safari/iOS and "Hide IP address from trackers" option[3] in MacOS/Safari [1] https://support.apple.com/guide/icloud/set-up-icloud-private-relay-mm7dc25cb68f/icloud https://support.apple.com/guide/icloud/set-up-icloud-private... [2] https://support.apple.com/library/content/dam/edam/applecare/images/en_US/icloud/ios15-2-iphone-12-pro-settings-cellular-cellular-data-options-limit-ip-address-tracking.jpg https://support.apple.com/library/content/dam/edam/applecare... [3] https://appletoolbox.com/wp-content/uploads/2014/02/Hide-IP-Address-From-Trackers-Mac.jpg https://appletoolbox.com/wp-content/uploads/2014/02/Hide-IP-...
- _kb 3y agoIt does with encrypted DNS (I think - still mid setup). If you use a configuration profile [0] to explicitly set a DNS over HTTPS or DNS over TLS server this is still honoured within private relay. IMO vanilla private relay is much neater and simpler if privacy is your goal. It uses Oblivious DNS over HTTPS [1] which is pretty neat. To trade some of that privacy to reduce ads setting up encrypted DNS restores filtering control. This does mean you then need to funnel those queries somewhere likely less oblivious though. Current setup I'm playing with in the homelab uses Adguard Home for filtering. This then forwards to a local Unbound instance acting as a recursive resolver with strict DNSSEC [2] and QNAME minimisation [3]. End result is the DNS traffic is still open, but does not all go to any one single entity (apart from my ISP, which can see TLS SNI anyway). [0]: https://dns.notjakob.com https://dns.notjakob.com [1]: https://datatracker.ietf.org/doc/html/rfc9230 https://datatracker.ietf.org/doc/html/rfc9230 [2]: https://datatracker.ietf.org/doc/html/rfc7816 https://datatracker.ietf.org/doc/html/rfc7816 [3]: https://datatracker.ietf.org/doc/html/rfc9364 https://datatracker.ietf.org/doc/html/rfc9364