A DNS filter is no protection lol
Comment on Smart TVs take snapshots of what you watch multiple times per second
Corporate_Hippie@lemm.ee 3 months ago
Use a pihole people, don’t go barebacking the internet
rimjob_rainer@discuss.tchncs.de 3 months ago
Onsotumenh@discuss.tchncs.de 3 months ago
Doesn’t help if the device has a baked in DNS address and just ignores your settings tho. Amazon and Google devices seem prone to that. After blocking everything on the common DNS ports except the PiHole, some of my devices have been acting kinda sluggish.
thatsnothowyoudoit@lemmy.ca 3 months ago
Easy to block that - though not with pihole.
We use another tool at our network edge to block all 53/853 traffic and redirect all port 53 traffic to our internal DNS resolver (works much like pihole).
Then we also block all DoH.
Only two devices have failed using this strategy: Chromecast - which refuses to work if it can’t access googles DNS. And Philips Hue bridges. Both lie and say “internet offline”. Every other device - even some of the questionable ones on a special VLAN for devices we trust work just fine and fall back to the router-specified DNS.
Onsotumenh@discuss.tchncs.de 3 months ago
I wanted to do that as well, but I can’t redirect outgoing traffic on my router, just block it entirely. Sadly it was the only device of that series not supporting OpenWRT (sigh)… Next one will either have to support that or be a DIY project… Have been starting to self host my stuff already and I’m not planning to stop there!
thatsnothowyoudoit@lemmy.ca 3 months ago
Sweet. It’s worth it IMO. And definitely fun for either tinkering or just having something solid that works (why not both? ;) ).
We’ve been using monowall - now pfsense since 2008.
I don’t necessarily recommend btw - there are lots of great options out there (like it’s cousin OPNSense and so many more).
wewbull@feddit.uk 3 months ago
How do you identify DoH Vs normal web traffic?