5 ms·
Why use pihole? Most OSes have a hosts file you can edit if you're just blocking one domain.
by nosrepa 1y ago
Why use pihole? Most OSes have a hosts file you can edit if you're just blocking one domain.
- Zolomon 1y agoIf you have multiple devices on the same LAN, all of them will use the pihole.
- 3eb7988a1663 1y agoWhen the nefarious actor is already inside the house, who knows to what lengths they will go to circumvent the protections? External network blocker is more straightforward (packets go in, packets go out), so easier to ensure that there is nothing funny happening. On Apple devices, first-party applications get to circumvent LittleSnitch-like filtering. Presumably harder to hide this kind of activity on Linux, but then you need to have the expertise to be aware of the gaps. Docker still punches through your firewall configuration.
- cluckindan 1y agoSet up your router to offer DNS through pihole and everything in your network now has tracking and ads blocked, even the wifi dishwasher.
- godelski 1y agoEven the dishwasher that has Wifi that you don't know has Wifi and will happily jump onto open networks or has a deal with xfinity
- bangaladore 1y agoUntil everything starts using DoH (DNS over HTTPS). There is pretty much no reason to use anything else as a consumer nowadays. In fact, most web browsers are using DoH, so pihole is useless in that regard.
- jamespo 1y agoYou can disable that
- bangaladore 1y agoSure, but the industry is moving in that direction so prepare for the uphill battle.
- efitz 1y agoNot true, see answer above. Block the domain name or IP addresses of the DoH server.
- cluckindan 1y agoYou can make pihole work with DoH: https://docs.pi-hole.net/guides/dns/dnscrypt-proxy/ https://docs.pi-hole.net/guides/dns/dnscrypt-proxy/
- meindnoch 1y agoHate to break it to you, but /etc/hosts only works for apps that use getaddrinfo or similar APIs. Anything that does its own DNS resolution, which coincidentally includes anything Chromium-based, is free to ignore your hosts file.
- gruez 1y agoBut pi-hole seems equally susceptible to the same issue? If you're really serious about blocking you'd need some sort of firewall that can intercept TLS connections and parse SNI headers, which typically requires specialized hardware and/or beefy processor if you want reasonable throughput speeds.
- neurostimulant 1y agoI configured my router to redirect all outbound port 53 udp traffic to adguard home running on a raspberry pi. From the log, it seems to be working reasonably enough, especially for apps that do their own dns resolution like the netflix app on my chromecast. Hopefully they don't switch to dns over https any time soon to circumvent it.
- efitz 1y agoDNS over https depends on the ability to resolve the DoH hostname via DNS, which is blockable via PiHole, or depend on a set of static IPs, which can be blocked by your favorite firewall.
- gruez 1y agoA sufficiently spiteful app could host a DoH resolver/proxy on the same server as its api server (eg. api.example.com/dns-query), which would make it impossible for you to override DNS settings for the app without breaking the app itself.
- dishsoap 1y agoor it wouldn't even need to use any sort of dns. bit of a silly discussion.
- charcircuit 1y agoThe hosts file doesn't let you properly block domains. It only lets you resolve them to something else. It's the wrong tool for the job.
- rs186 1y agoSo that these domains are automatically blocked on all devices on a local network. Also, you can't really edit the hosts file on Android or iOS, but I guess mobile OSes are not part of the discussion here. Although there are caveats -- if an app decides to use its own DNS server, sometimes secure DNS, you are still out of luck. I just recently discovered that Android webview may bypass whatever DNS your Wi-Fi points to.