3 ms·
>I do not use public DNS such as Google or whatever, in fact, they are all blocked. Honestly surprised that works given Google loves to hardcode DNS queries us
by HDBaseT 4mo ago
>I do not use public DNS such as Google or whatever, in fact, they are all blocked.
Honestly surprised that works given Google loves to hardcode DNS queries using their DNS Resolver into many things (Google TV, Android, etc).
I'm assuming you are using NAT Redirection (Port 53), blocking DNS over TLS - DoT (TCP Port 853), using SNI FIltering to block DNS Over HTTP (DoH). Not sure how you handle Encrypted Client Hello.
- h4kunamata 4mo ago>Honestly surprised that works given Google loves to hardcode DNS queries using their DNS Resolver into many things (Google TV, Android, etc). My Samsung smartTV has Google DNS hardcoded in it, that is why I do what I do. No matter if I set my phone DNS to Google, OPNSense NAT redirects any DNS to Piholes only, and since public DNS, DNS-over-TLS and DNS-over-HTTPS are blocked, only Piholes forward it to Unbound. Only Unbound can request DNS and OPNSense enforces that. Unbound is recursive DNS with is own caching so everything happens localy, surfing the internet is insane fast. As for the digital ID, the DNS happens locally but the traffic is forward to Mullvad VPN Gateway. I don't wanna hide my traffic, I just don't wanna this mass survilance on my personal information. My social media accounts are burner, no real name, no photos, minimal apps installed on my GrapheneOS phone and I have a complete normal digital life without sharing my shit haha
- ralferoo 4mo ago> ..., DNS-over-HTTPS are blocked Not trying to be facetious, but how do you know you are blocking them all? I thought one of the reasons for using DNS-over-HTTPS was to be able to avoid detection.
- h4kunamata 4mo agoYou aer mixing two things together, and popular misundertanding: You cant never truly hide your DNS requests, your ISP can still see the traffic. There are plenty of videos showing how you can use WireShark within your network to identify packages flagged as DNS, no matter if DNS, DOT, DOH, they have identifiers making it easier to identify them by analysing the packages. You just need to know how. If your ISP really wanna know what you are accessing, they can, DOH isn't VPN. 1. Icannot just block 443, I have an aliases with every known public DOT and DOH on OPNSense 2. The firewall blocks any requests to those IPs on port 443-DOH and 853-DOT If I type on my browser 8.8.8.8:443, it does not work and OPNSense firewall log shows the block message, so DOT:853 and DOH:443 are fully blocked.