• Welcome to ASR. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

The internet is breaking down - or so it seems. Reddit is now unaccessible.

gr8. thanks for taking the trouble to answer.
Unbound as local dns server for pihole. Makes upstream routing of dns obsolete. Alternative would be DoH/DoT upstream to cloudflare f.e. - but I don't like the performance and that they could profile. Upstream routing of unencrypted dns is subject to monitoring and should be avoided. But still better than provider dns, which unlocks all bad things.
i've used unbound in the past but was unsure how to configure it. in a basic set up unbound makes queries the authoritative servers in what protocol? the reason to go down this road is to not give all our DSN queries to Verizon. but if unbound is querying the authoritatives in plaintext then i haven't solved anything. dnssec is for authentication, not privacy. i recall using dnscrypt for a while but then i had to find upstream servers to connect to, which has the same issues as over HTTP you noted.

Pihole can also do DHCP.
good point. looks like i can disable DCHP service on the Verizon router so running it on pihole might mean i don't need to screw with another router.

A small Pi4b and an sdcard is enough for all of this and ~1mln blocklist entries from a dozen public lists or so.
it's a 4b that i've been using all these years. it also runs plexserver and lyrion for us.

For mobiles Blokada does the job everywhere. It works a bit different as a vpn tunnel, but the principle of blocklists and custom entries is the same, plus lists of apps. DNS is upstream encrypted.
i'll look into it.

thanks again.
 
i've used unbound in the past but was unsure how to configure it. in a basic set up unbound makes queries the authoritative servers in what protocol? the reason to go down this road is to not give all our DSN queries to Verizon. but if unbound is querying the authoritatives in plaintext then i haven't solved anything. dnssec is for authentication, not privacy. i recall using dnscrypt for a while but then i had to find upstream servers to connect to, which has the same issues as over HTTP you noted.
Well, a dns server loads zones from upstream for his local work. And does not disclose the specific request, it's nature, attributes or if it happened at all. That's obfuscation, not encryption. But still a good measure.
 
good point. looks like i can disable DCHP service on the Verizon router so running it on pihole might mean i don't need to screw with another router.
Yes, absolutely. Routers have different concepts. The gateway and dns not being subject to change is a default here and there. But the possibility to disable dhcp (and other things like wireless) is usually given.

Splitting up router/gateway - dhcp - dns - does not break anything in a localnet. These things do not need to be on one host.

Pihole's dhcp server is actually pretty good. All the necessary options, reservations, even domain/workgroup/samba integration has been thought about. If you want more options handed out to the client than the GUI offers, it needs to be put in a config file though.

While we are at it, here is a list of my gravity entries. I have like 5 exceptions to those, but that will be subjective. Maybe the blocking of smarttv shenanigans and what brands in this section do is of interest to others. I first looked into that when the NVidia shield was "upgraded" to ads.

https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
https://raw.githubusercontent.com/RPiList/specials/master/Blocklisten/Win10Telemetry
https://raw.githubusercontent.com/RPiList/specials/master/Blocklisten/MS-Office-Telemetry
https://raw.githubusercontent.com/RPiList/specials/master/Blocklisten/samsung
https://v.firebog.net/hosts/Easyprivacy.txt
https://v.firebog.net/hosts/Prigent-Ads.txt
https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.2o7Net/hosts
https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocker/master/data/hosts/spy.txt
https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt
https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/android-tracking.txt
https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/SmartTV.txt
https://big.oisd.nl
https://raw.githubusercontent.com/blocklistproject/Lists/master/ransomware.txt
https://raw.githubusercontent.com/blocklistproject/Lists/master/facebook.txt
https://raw.githubusercontent.com/blocklistproject/Lists/master/tiktok.txt
https://raw.githubusercontent.com/anudeepND/blacklist/master/adservers.txt
https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-domains.txt
https://phishing.army/download/phishing_army_blocklist_extended.txt
https://raw.githubusercontent.com/d3ward/toolz/master/src/d3host.txt
https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/ultimate.txt
 
Hi

I am in IT and , at times, I sincerely wonder how the Internet even manages to work... Let alone as well as it does: to the point of supporting most of Earth communications... in a quasi-reliable fashion.
On the privacy part, I am alarmed and often, feel powerless. There are many and various measures, but their level of protection depends on a level of knowledge that few casual, even informed Internet users possess. And a vigilance that few peple , even professional can muster .... And with the rise of AI, we are even more exposed on that front, privacy, than we have ever been.
...
Sobering.
 
Yes, but regardless of skill level I suggest to not give up. Everyone can achieve some better level of security/privacy/data protection. And with more skills more is possible. This is unfortunately not a black/white situation but a wide grey area where we never get to white.

Just look at what capable adblockers achieved. A simple ublock origin addon installation with default settings frees anyone of 99% of the most obvious crap out there. Did they fight it? Sure they did! But open source software won that one.
 
As one who followed the development of the internet with modem over telephone line and the first browser Mosaic and second Netscape up to Firefox I appreciate very much the internet as a real valuable resource and platform for purchasing. Of course I am aware that there is no real security for data. And if you want to place a order at webshop anyway you need to provide some of your data. And there you lose control where the data will go to and who has access to it. So my intent is to provide as few data as possible if needed. And all one puts into a forum or else will stay virtually for ever. That is the way it is. Most important is the awareness of it and to be careful. There is no 100% protection whatever software vendors tell you. Most of the problem is that some people react on all what comes in and click on links in phishing mails.
 
Last edited:
Yes, but regardless of skill level I suggest to not give up. Everyone can achieve some better level of security/privacy/data protection. And with more skills more is possible. This is unfortunately not a black/white situation but a wide grey area where we never get to white.

Just look at what capable adblockers achieved. A simple ublock origin addon installation with default settings frees anyone of 99% of the most obvious crap out there. Did they fight it? Sure they did! But open source software won that one.
Trouble is, if getting fairly good at it at an amateur level, your "profile" stands out and shines like the sun at midsummer. Switch off your iPhone and it works as an AirTag, walk about with earbuds, they are linked to your device and tracked. And Google&Co gets their info from all sources they ping wherever you go. Play music with Tidal, Spotify, Qobuz or Deezer, everything "secured" with VPN and what not, they are still able to put you within 10 feet of your actual location. Together with your mistress or same sex secret which is sensitive and potentially exploitable info.

Got something wifi not able to cut the power, and it pings everything from your TV to heavens knows what. I got at least 30 (50 is more like it) routers bestowed with Google within range of my desk. One can secure a celluar phone (Jolla/Volla and what not), but no average user have any idea whether and if so, how much, info Verizon and all their competitors are selling. Google infesting routers is evidence of the attractiveness of such info.

The only thing which actually may provide helpful is if lawmakers put their foot down, but they won't as just about every government/state in the world benefits from the access to info about their law obeying citizens. Like Switzerland who have used their courts to get info, and are working to make access mandatory.

One can only do so much whilst still being able to use an electronic device with some sort of meaning, but unless laws and very heavy sanctions as part of those laws are implementet, users are pretty much lame ducks. I ended up with sticking to Mullvad VPN/Dns/Browser set up as strict as I can, but I am under no illusion about my digital safety and privacy. I see this as the reality and if any of my arguments are wrong or inaccurate, I apologize and welcome any preferably competent contradiction :)
 
Fall back to Nokia phone
Matrix-payphones-disappearing.jpg
 
Back
Top Bottom