I've had a pi hole on a pi zero with an ethernet adapter for years now and the best part is blocking ads inside free programs and the like
@alexanderliverierolavelli19994 жыл бұрын
and also in all android apps
@sarkybugger50094 жыл бұрын
My PiHole is on a Pi Zero W plugged into the router's USB port. Only one wire required. :o)
@stranger79684 жыл бұрын
I've been using Pi-hole for 3 years now. The amount of things trying to get call home is staggering(telemetry). I noticed that some "smart" devices get really aggressive with their calls if you block them.
@jothain4 жыл бұрын
Yeah. I was looking myself logs that what on earth on my home network was so aggresive. Turned out to be Samsung TV.
@MrLuNa774 жыл бұрын
Let met guess... Samsung smart TVs ? I just plugged it off -.-
@stranger79684 жыл бұрын
@@MrLuNa77 Yup Samsung. I have since unplugged it. The "smart" functionality of the tv is not that useful anyways when there are other devices plugged into it. I think another offender was my tp-link smart socket. It's on a separate IOT wifi network now.
@Bob_Smith194 жыл бұрын
Roku doesn’t stop once you block it. Amazon devices are really bad as well.
@theeiszeitmann9284 жыл бұрын
PI-hole + Wireguard and DynDNS and you never have to look at an ad again ;-) not even on your Phone on the go. But i would always build the NAS/Home-Server myself.
@timothycarr4 жыл бұрын
"Do you want to run a raspberry pi in your closet for 4 years?" Me: *Stares nervously at my first gen RPi still running my DIY smart power strip after 6 years*
@turbo55464 жыл бұрын
I love my pi-hole I've been running it for years. I think everyone should have one on their network.
@Englishneo2k4 жыл бұрын
I've got it running on a pi2 along with pi-vpn using wireguard. So hand, cheap to run and easily runs both and have it also running dhcp as well. Its great as I can VPN into my home and then I get the filtering when off WiFi. Have it reboot once a week and since 5.0 update is great and can add devices to groups if people complain they can't buy things via Google links...
@jaystannard4 жыл бұрын
Wendell, when I was first starting SQL there was a book "SQL in 10 minutes" that was about 50 pages long with the really basic concepts. Is there a similar book for networking?
@grin644 жыл бұрын
Take a comp-tia course.
@marklewus5468 Жыл бұрын
I know this video is 3 years old but something you said triggered me. Raspberry pi can run for a very long time. I built a magic mirror in early 2019 based on a pi 4. It has been running for those 5 years with only annual OS security updates, and no app maintenance. The hardware has run 24/7 with zero failures, not even the SD card.
@OwlishGeorge3 жыл бұрын
Yep, I've got a few Pi's running for a few years now. The only 'maintenance' I've done is to ssh into them as part of my monthly update routine for all my homelab/connected crap. Definitely been more reliable than my damn cable modem!
@jamesleehunter4 жыл бұрын
But how do I stop the false positives, like ads I intentionally click or things that aren't strictly ads?
@TrollingAround4 жыл бұрын
When advertisers realise their ads aren't generating income, the dead shall walk the earth.
@databang4 жыл бұрын
Thanks for your continued Synology coverage!
@kelvinjamesvictoria48853 жыл бұрын
What are the adlists you recommend?
@Appalling684 жыл бұрын
Watching your fine video with my Raspberry Pi Zero loaded with Pi-Hole plugged directly into my router. Love it!
@mediis4 жыл бұрын
i really enjoyed the part where he says, "edit resolve.conf" and the text in resolve.conf says, "DO not edit this file". He's talking like a traditional System V Unix Admin, not a modern day Systemd Linux Admin.
@VigneshBalasubramaniam4 жыл бұрын
Its also worth checking out nextdns.io. Its essentially a cloud based Pi-Hole. You can choose how long the logs stay up, and the physical location of the server that contains your logs. This say, you can have the convenience of Pi-Hole everywhere you go, and its guaranteed to stay up. Nextdns also supports DNS over TLS, and DNS over HTTPS. I've set my OpenWrt router with DNScrypt to use DoH, and my LineageOS Android phone to use DNS over TLS (which Android 9 and up natively supports).
@thomas.becker4 жыл бұрын
the problem with pi-hole and synology (or nas in gerneral) is that it never enters hdd hibernation. most home users will use that feature. a raspberry zero will save a lot of energy und hdd wear compared to a 4 bay+ nas but i get it - synology sponsor money...
@WesSites4 жыл бұрын
Or... and hear me out... you could throw an SSD into your NAS and run pinhole on that ¯\_(ツ)_/¯
@pieterrossouw85964 жыл бұрын
Running on Unraid I can run the PiHole docker without spinning up any of the HDD drives. Just have an unassigned drive like an SSD or even a flash drive and move your docker image there. Also makes docker containers extract and start up much faster.
@SoundToxin4 жыл бұрын
To counter this (valid) point, Pis will absolutely destroy SD cards, and it's actually recommended to use USB storage for long-term use, whether flash drive, external HDD, or external SSD. The blame isn't entirely on the Pi, for some reason SD cards just seem to fail more than anything else.
@pieterrossouw85964 жыл бұрын
@@SoundToxin Berryboot solves this pretty well and gives you additional features.
@thomas.becker4 жыл бұрын
@@pieterrossouw8596 but this won't work on consumer grade NAS enclosures (synology, qnap, etc). which this is clearly addressed to. there's always a more professional solution , but for the average user a pi-hole with a pi (zero) would be easier than buying and setting up a unraid system.
@MyTv-3 жыл бұрын
What’s a intrusive ad change mostly depending on if your on the delivering or reserving end!
@wfp93784 жыл бұрын
I have tried running it on a Synology 1819+ and while I can get into the webmin interface, the docker complains about ports 443, 53 and 67 being used by other services. I suspect it is because I am already using my Synology as the DHCP server for my network. Would that be the issue here? If so is there a way around this?
@frollard4 жыл бұрын
I haven't tried it at the dns level yet - do websites with 'you have an adblocker' nags complain of this dns level block?
@MrCheezeus4 жыл бұрын
Not that I've noticed, the disable ad blocker notification hasn't shown up, even on sites that I know pop up with the notification with a normal ad blocker.
@MrCheezeus4 жыл бұрын
Got something like 1.15 mil sites blocked on my pi hole... still have ads slip through, even with 50-70% of all dns requests being blocked 😑
@prstorero4 жыл бұрын
I have everything set up like it was demonstrated, and it works on my computer if I set the dns server, but using that same IP on my Google WiFi causes no pages to load after restarting the network to make the change take effect. I would like to apply it network-wide with the router, but I'm struggling to make it work.
@uncleslapslap4 жыл бұрын
I want PiHole and LanCacheBundle but I run a domain controller at home (big family) and can't get group policy to work if DNS or DHCP are not coming from the DC. Any ideas around this?
@chromefinch4 жыл бұрын
I'm surprised he didn't mention DoH (DNS over HTTP). You'll want to add that list so your browser doesn't ignore your local DNS.
@cosmicrider58984 жыл бұрын
Dns crypt is more secure
@cosmicrider58984 жыл бұрын
But you could use all three (doh, dot,dnscrypt) plus dnssec
@chromefinch4 жыл бұрын
@@DistantComputer i totally missed that.
@mr49783 жыл бұрын
docker isn't supported o. my ds218 :( I tried manual install but its saying its unsupported
@seanwoods15263 жыл бұрын
Does the Docker image support a recursive DNS setup?
@tehsimo4 жыл бұрын
Can you do a tutorial on combining pihole with unbound/cloudflared to get encrypted dns too?
@bobcarpenter15514 жыл бұрын
docs.pi-hole.net/guides/dns-over-https/ If you are comfortable cutting and pasting into an SSH console those instructions are fairly easy to follow.
@daveninjaneuro70893 жыл бұрын
Will this work with Qnap nas?
@mr.lineleaf81114 жыл бұрын
how to do this on pfsense? Got pfblocker but its not enough. mybe its done through firewall rules, though thatll take to long to make.
@jouldalk4 жыл бұрын
Thanks Could you please point to introduction videos about what docker is and how it works on Synology NASes?
@donelgwapo4 жыл бұрын
Does it block KZbin ads?
@brendonjones2904 жыл бұрын
I still prefer pfblockerNG on pfsense which I set up for about $100, but this is great for those who already have a Synology and want to keep it together. Pfsense obviously offers lots of other fun things too.
@ross48144 жыл бұрын
I clicked on this video to dig into Wendel's channel looking for his NAS videos, found something far cooler. This is awesome.
@zakariamahhouti8914 жыл бұрын
Does Pi-hole block KZbin ads on mobilephone?
@CFord2564 жыл бұрын
-9:50 some cheap Synology NAS units don't support docker.
@jfletcher10294 жыл бұрын
None of the ARM based ones support it. Only Intel.
@JonahFarve4 жыл бұрын
I like what Pi-Hole does, and I like that it will track users so you can view who's looking at what in the Dashboard. Very useful if you have kids. However, it doesn't play well with Active Directory. Setting Pi-Hole as a forwarder in AD DNS is fine so users can login, but the Dashboard stops being useful as it only see's DNS requests from the AD DNS server. I wish there was an AD/LDAP plugin for it.
@dragonfist4 жыл бұрын
as already a user of pihole I cant imagine the life without it
@McCornville4 жыл бұрын
I’ve had pi hole on my pi for a while now. My only issue is websites not letting you view the page unless you disable pi hole
@BoraHorzaGobuchul11 ай бұрын
There has to be a convenient way to bypass filtering for those few that are worth it, I suppose, would like to learn that
@Baxtexx4 жыл бұрын
I have used pi hole a couple of times. My main issue is that the pi doesnt handle power cuts very good. So every now and then the memory becomes corrupt and I have to reinstall which drives me nuts.
@timfreeeed4 жыл бұрын
Thank you! Can we talk lists for a moment? Did the piHole change to regex or something similar? I configured the piHole lists on my pfsense dnsbl 2 years ago but it's not yet capable of doing regex url's. I think that's the reason why I still have ads in certain apps (Twitter). Is that correct?
@caseyhefner19664 жыл бұрын
Yes, you can do Regex on Piholes now.
@chromefinch4 жыл бұрын
They got rid of the list of adlist for a database of adlists, so you have to use their teleport backup and recovery tool
@kenzieduckmoo4 жыл бұрын
the major problem with pihole is finding good blocklists to actually stop all the ads, cause by default it doesnt actually block anything
@springbok40154 жыл бұрын
How did you allow port 53 on docker? I get a port conflict with my Synology. I’d rather set it’s own static IP. I’m not a huge fan of Pi-Hole. I think Adguard Home may be better? Or even Cisco Umbrella
@grim.reaper4 жыл бұрын
Awesome content, have been waiting for this. Now please make a video about running your own VPN 🥺
@just_curious29274 жыл бұрын
@Neon Rogue slooooow
@vgamesx14 жыл бұрын
Really the VPN is the easiest part, if you're going to rent a VPS or something, just simply making sure it's secure and setting up stuff like docker will take far longer than almost any service you want to run, double that if you want to do things proper by routing things through a reverse proxy and use a domain name (traefik ruined my excitement for finally setting up a home server).
@pieterrossouw85964 жыл бұрын
PiVPN is probably the easiest way to get OpenVPN or preferably WireGuard running. I've got it running on a little Ubuntu VM at home so I can VPN into my network. You can easily spin up a nano or micro EC2, assign an elastic IP and VPN in there if you trust AWS with your traffic... The how isn't hard, it's where to run it that has become a minefield. Linode might be great and respect privacy (or not, I don't know) but they certainly don't have servers in every region.
@thetechnoguy20104 жыл бұрын
This only works if you ensure a port 53 redirect. If an application or appliance has DNS:8.8.8.8 hard coded it will bypass the DNS server filtering. You should add something to the firewall that does a NAT redirect for port 53. Source: destination: port:53 NAT to ... did this with PFsense.
@lordstevewilson13314 жыл бұрын
Mine cant bypass, I have set firewall rules to block all dns requests to internet if they are not from my pi-hole.
@Arokhantos3 жыл бұрын
If you wanna do it properly you make a macvlan from command prompt without ip range and make the container from shell with mac id and ip asigned and thru macvlan
@BobPegram4 жыл бұрын
DNS is IP version blind, correct? Does anything work differently on IP Version 6?
@Cadillac18624 жыл бұрын
could this be done with the synology router?
@Firecul4 жыл бұрын
Did not think of using my nas for this, I'll definitely try setting this up later
@karlschuneman79604 жыл бұрын
I guess Docker is not available on "ALL" Synology boxes. I have a DS218j, Docker is not an installable item. Thanks, but I'll stick with the PI.
@WongTag4 жыл бұрын
Same here... x86 wasn’t common on Synology, or NAS in general, until recently. With the success of Docker it’s been disappointing to say the least.
@richards79094 жыл бұрын
It seems the low end Synology NAS don’t support docker which I find a shame. Not sure why, perhaps CPU related.
@jfletcher10294 жыл бұрын
Richard S ARM based nas won’t be supported. Only Intel.
@Kushari4 жыл бұрын
Has to have an intel CPU.
@Kushari4 жыл бұрын
@@richards7909 It's not low end. I have a 8 bay one. It needs an intel CPU.
@LampJustin4 жыл бұрын
Does anyone use DNS blocking using BIND9, if so can you please hint me in a direction?
@deskgrunt4 жыл бұрын
I use DoT - DNS-overTLS with Cloudflare on my router ( Asus with Merlin firmware) . Is it possible to configure PiHole to get it's dns-lists from that?
@bobcarpenter15514 жыл бұрын
Not the lists but its queries: docs.pi-hole.net/guides/dns-over-https/
@alymuni4 жыл бұрын
People should check out "notrack" its basicly pihole on stereoids.
@MrV1NC3N7V3G44 жыл бұрын
And what if your AT&T modem/router will not let you change the DNS? I've searched the net and many people have this issue.
@lordstevewilson13314 жыл бұрын
Plug your own router to at&t modem/router and then plug your devices into your own router.
@MrV1NC3N7V3G44 жыл бұрын
@@lordstevewilson1331 I tried that at one point and it was still using the AT&T DNS. Maybe it was how the 2nd router was attached.
@JJFlores1974 жыл бұрын
@@MrV1NC3N7V3G4 If you have AT&T U-Verse, you will need to setup IP Passthrough on the AT&T gateway in order for the 3rd party router to work correctly. There is no bridge mode on U-Verse like there was with the legacy DSL service from AT&T.
@MrV1NC3N7V3G44 жыл бұрын
@@JJFlores197 I'll try that when I find the time to reconfigure everything in the house again. I think the first time I just connected the 2nd router via an ethernet port and let my AT&T router do all of the DHCP.
@cyberwasp4613 жыл бұрын
Newbie here. Could you give me a link to a video that actually shows how to setup pihole
@Kushari4 жыл бұрын
It's not any synology. It's any synology that has an Intel processor. Docker doesn't work on non intel CPU Synologys.
@antaishizuku4 жыл бұрын
Great video, the one complaint i have is that there isn't a adlist for us to go off of.
@MikeS293 жыл бұрын
I will watch this 4 more times before I start :-)
@pieterrossouw85964 жыл бұрын
What happens when DoH and DoT gets ubiquitous? It would seem there's a bit of an arms race. The user has finally "won" with simplified DNS level blocking, so the next solution to deliver ads will not need DNS. What's next?
@weasalnz14564 жыл бұрын
I keep seeing people say AdGuard is better than Pi-Hole and visa versa what do you think?
@mausilugner66374 жыл бұрын
for non synology users try vmware or virtual box with dietpi image and install pihole by yourself
@comgreed4 жыл бұрын
I don't like to type ip:port in the browser. Instead I use vhosts proxy redirects in Apache + custom DNS entries.
@billcarson19664 жыл бұрын
I'm screwed on this option for now. I've got Comcast and their XFi Gateway locks in their DNS servers. I have no way to override it for now. My pfSENSE router died and if I'm going to get into all that again, I'd just skip Pi-Hole and use pfBlocker and Suricata. For now, I'll just leave it as it is. :-(
@Onlymagics3 жыл бұрын
Love my Pi-Hole, running it in an Ubuntu Server VM on my R815, have it doing recursive DNS and DHCP for my VLANs, awesome program, do recommend recursive DNS!
@hammerheadcorvette44 жыл бұрын
The PIA (privateinternetaccess) mobile app work like a pihole if you ge the one fromn their website and not the Play store
@smerhawk4 жыл бұрын
I would love to set something like this up, but I don't have a home server. Do I need one? I mean I really don't do anything other than play games and watch youtube/hulu.
@ecnctggc4 жыл бұрын
Pi-Hole was originally designed to run on a Raspberry Pi. These can be bought for just $30 and ~is~ *are* more server than you ever need for this kind of stuff.
@smerhawk4 жыл бұрын
@@ecnctggc cool, tyvm
@ClintPhipps4 жыл бұрын
Is there a benefit in using pi-hole over pfblocker?
@bobcarpenter15514 жыл бұрын
IMHO, no. pfBlockerNG can use the same blocklists that PiHole does, doesn't require additional hardware/docker/VM etc. as well it can do Geoblocking. I ran PiHole for about a year before switching. Both work well, pfBlocker can do more. You're not playing whack-a-mole against people/devices casually bypassing your DNS by "going right to the gateway/router."
@tropmonky4 жыл бұрын
I love my PiHole!!!! currently blocking 51.7% of inquiries! That's NUTS!!!! Do you know of some GOOD blocklists?
@mindustrial4 жыл бұрын
Pi Hole doesn't really filter Facebook that well, because Facebook uses very nasty scripting and nesting to hide/obscure their ad blocks
@AndreVandal4 жыл бұрын
Amazing how people seem to be getting static IP so easily, where I am my ISP charges an arm and a leg for one. I wish there was a way to just use the normal IP and setting would simply change itself when the IP changes.
@paspa074 жыл бұрын
It's not WAN IP but LAN IP that has to be static. I think you can set that on your router without your ISPs say.
@lifebarier4 жыл бұрын
Any good reason to trust pi-hole over pfblocker?
@chromefinch4 жыл бұрын
It's prettier
@nictou4 жыл бұрын
why trust any software? look and verify yourself
@lifebarier4 жыл бұрын
@@nictou That does not help with answering my question. I do not have time to verify someones side projects like pi-hole, and I doubt many has such time. But pfblocker has more eyes on it.
@nictou4 жыл бұрын
@@lifebarier ..then the answer is "no". Different use cases . I needed a network-wide blocker/filter and do not have a home lab to play with. So i use a pi3 under my shoe shelf. Simple "plug and play" ... DietPi as OS and one wget command. This more for the "wife Factor" than for a production environment.
@lifebarier4 жыл бұрын
@@nictou I disagree with "different use-cases", from the way you put it it seems that pi-hole is just poor mans pfblocker.
@ashishpatel3504 жыл бұрын
"their pipe is not fat enough" - wendal 2020
@sirius4k4 жыл бұрын
wendal?
@Mr.Leeroy4 жыл бұрын
@@sirius4k vandal
@bigchew31494 жыл бұрын
Cool Video ! I Have Ran PiHole Now For4-5Years on a home server & I Think It Is The Best Thing Sense Sliced Bread ..Well If You Hate Ads As Much As Me That Is ! I Use pfsense As well for 5-6 Years i just have not masterd it Yet With pfblock & my plex server,and some game servers & So Pf Sense & fire fox adon ad dblock+ & i Would Say they Stop 99% oof the pesky ads ..I Have a Custom list i tweked/Modded That Seams to work well..even though i did have a problem with youtube ads still poping up bfor ever video for a short time but that is all fixed,easy to do & just plain fun ! Any Tech guy/nerd or it guy is & Should probably B running this or something close to it !
@praxis224 жыл бұрын
I paid for BeOS back in the day, got a book and a t-shirt :)
@zushiba4 жыл бұрын
Can I just buy one of the cheap $5 Linode instances, install Docker on that and run PiHole through Linode as a custom DNS server & VPN when I'm away from home?
@lordstevewilson13314 жыл бұрын
Yes you can, but it's a lot more complicated.
@darkavenger10k4 жыл бұрын
I do quite like the PiHole project, personally I'm currently using OpenWRT with the Adblock application which does the same DNS blocking but doesn't have a nice interface like that.
@edwinconcepcion11354 жыл бұрын
Pihole+Adblocker plus+noscript+PrivacyBadger+CookieAutoDelete+WAF+DPI=Surfing without so many ads :)
@eseseis72514 жыл бұрын
careful, many devices and software have dns servers hardcoded, so in firewall or router software i only allow 1 lan ip to connect to external 53 port. thats pihole ip.
@idontwantachannelimjustcom77454 жыл бұрын
I remember beos. We had to install the demo version that had the file system that ran inside of a file..... the teacher told us not to bother with setting up internet, because it didnt work.... then he look over at me surfing the web, with a confused look on his face.
@CYellowan4 жыл бұрын
Brilliant. It's adblock on steroids 💪
@97682364 жыл бұрын
The only thing I wished Pi-Hole managed to do was block KZbin ads. However that's pretty much impossible due to how Google injects ads from the same url as the video itself, thus blocking the ad blocks the video. You should give a tutorial on setting up encrypted DNS on the thing as well. Especially considering both Google and OpenDNS has ECS (Extended Client Subnet) and Pi-Hole even warns you about using those DNS servers. DNSCrypt has some anonymized DNS features now that makes DNS lookups completely anonymous.
@BoraHorzaGobuchul11 ай бұрын
There's plugins now for most browsers that block KZbin ads and generally make it easily usable (like removing unneeded blocks, easily adjusting playback speed including with a hotkey, and so on), and on Android office there's r Eva nСеD for that. Google breaks then sometimes by changing KZbin, but that happens not that often, and generally there's an update for that shortly available.
@GNARGNARHEAD4 жыл бұрын
whatever happened to those Snort for pFsense videos? :D
@dustinkrejci61424 жыл бұрын
OK so I’m trying to set up a WISP Internet business model for a million people, how do I set up pi hole to handle that traffic?
@sitte244 жыл бұрын
You shouldn't be using pihole at such scale, get something enterprise grade
@uninfamous4 жыл бұрын
Now use Pi-hole for the computer on your Level1 news videos. 😉 .
@maxmustermann1944 жыл бұрын
works in a VM on synology too
@dennis81963 жыл бұрын
Google is the least intrusive, except KZbin ad's. These have become really awful since the last policy change. I'd like Pi-Hole to spoof showing ad's. EG allow the page or document to load, but anything coming from a known IP / Domain of an advertiser should pretend to load on the Pi as if it was loading on the original page. Making it harder to detect ad blocking techniques. Harder, not impossible.
@jamescrook994 жыл бұрын
Wait I just got Linus pulseway ad before this video ?!? Mind blown
@marioramirez73554 жыл бұрын
Just found out that my Nas (214) can not run Docker :(
@kouji714 жыл бұрын
Deploying Raspberry Pi with PoE is really really cool.
@mondskiez3094 жыл бұрын
I have 2 piholes on the cloud for redundancy.. takes care of the daily 150k requests, 75k blocks using 2.4M blocklist domains across my home & office networks and more importantly when I'm on mobile..
@nictou4 жыл бұрын
super simple setup on my pi3. Blocking 40% of my network traffic at my fritzbox... and yes the samsung tv is the worst offender
@Nextrix4 жыл бұрын
I would suggest installing the official Cloudflared image in another Docker container so that you can have your DNS Upstream transferred over HTTPS (DoH).
@knightk5254 жыл бұрын
I believe we can set up steam dns to cloudflare in pihole.
@chocolatebrisket37724 жыл бұрын
What if I want to use a VPN too?
@MrFloRolf3 жыл бұрын
am i the only one who can't get it runnign with this guide? Did it change over the last year and a half? Any other guide online also makes many things different.
@RyeRyeL4 жыл бұрын
I run PiHole in a VM on my Plex server. It's great, no ads across everything
@MrKarator4 жыл бұрын
Nice info about ttl and dns malware but.... Why you didn't show how to conf docker network, cause using host ip is not best idea and what about linking directories and setting variables??? People who see this at first time will be disappointed why it doesn't work (((
@Level1Techs4 жыл бұрын
Huh? In the video the docker container is bridged to the host network via the Synology gui. Don't need to muck with docker net config....
@gorgonbert4 жыл бұрын
...and then the ad serving app starts running its own DoH 🙄
@Cheeky_Goose4 жыл бұрын
Wait, is this an actual possibility?
@chromefinch4 жыл бұрын
You just need to add another list, like an adlist or malware list, so a host list I guess. Hasn't gotten bad enough you need content filtering. But that will be next.
@stranger79684 жыл бұрын
It's only a matter of time. Then we have to block HTTPS requests to DOH from all hosts except for Pi-Hole.
@JonLinde4 жыл бұрын
@@Cheeky_Goose Yes, it's a possibility. Try looking at a Chromecast dongle... It's even more painful than that. There are normal DNS running on port 53 (can be both TCP and UDP but normally UDP). Then there are DNS-over-HTTPS (DoH) Finally, there are DNS-over-TLS (DoT). Any application can in principle have a preconfigured list of servers it can try to connect to, to attemt circumventing DNS filtering. To make matters worse (in this regard), a DoH service can run on any URL, and as the connection is encrypted, you can't really inspect it and block it specifically while leaving the rest of the site untouched. You are forced to block that host entirely. In my own network (pfSense firewall): - firewall rules will redirect any DNS request destined to external DNS servers to my own DNS (port 53). (pfSense with Unbound DNS and pfBlockerNG plugin for pi-hole-like functions). - any connections to public DoH servers (I know of), are blocked. - any connections to DoT ports (port 853) are blocked. Effectively, you have to try really hard to circumvent my DNS filters (but it's not a bullit proof setup I have made)
@TheRuneSnake4 жыл бұрын
And then we shall all make the great pilgrimage to the holy grail... Pfsense.
@scinexus2 жыл бұрын
I liked the video simply 'cause you told me to shut my pi-hole.
@Clozof4 жыл бұрын
I do this on a Remote Level using AdGuard DNS on PC and Mobile. Blocking Malvertisers on a DNS Level through a Remote Server, rather than a Local Server.
@JonLinde4 жыл бұрын
Pi-hole needs a resolving DNS server to forward DNS requests to. I recommend using Cloud9, as they do have some filters to help protecting you (and they don't log). Cloud 9 servers are predefined in Pi-hole. Maybe it would be appropriate for L1 to make a video about Cloud 9 and DNS security?
@sitte244 жыл бұрын
You mean Quad9 don't you? It's so simple to remember the name when looking at that IP
@JonLinde4 жыл бұрын
@@sitte24 :-D Shiit. I really hate my phone's multi-language dictionary... Now I wonder how many times it changed quad to cloud - without me noticing :-D
@treyquattro3 жыл бұрын
the thing I really worry about is when content providers figure out how to get around DNS (hosting all ads and crapware on their own network is a super-simple first step). I can even imagine a time when the people who killed net neutrality make it an offense to muck with anything that is served by a content provider! If you block ads, y'all's ass is goin' ter jail, boy!
@heminder4 жыл бұрын
These sites and apps will still track you via browser/device fingerprinting.
@heminder4 жыл бұрын
On phones and tablets (and maybe laptops) there is also IMU tracking, which is not talked about very much and doesn't require user consent. It uses gyroscopes, accelerometers, and magnetic sensor (compass). Can pinpoint your location with the dead reckoning method, guess what activity you're doing based on acceleerometer movements, and possibly listen to vibrations (audio) since these sensors are so precise on devices today.