home.social

#doh — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #doh, aggregated by home.social.

fetched live
  1. Докрутил до более-менее рабочего состояния. Не падает при нагрузке, резолвит и домены без ipv6 ns-серверов.

    Переключил трафик от небольшой сети ~100 пользователей через кэширующий dnsmasq - полёт нормальный.

    #selfhosted #dot #doh #dnssec #multednet #ipv6

  2. Inspired by Proton's post, I decided to get a new router instead of using just my modem/router combo. The primary driver was that while my #cable modem's modem functionality is fine for my service, the features on the router/wifi side were lacking, so it's not like I haven't been thinking about this for a while. The idea that my #ISP could be using my router's wifi antennas to spy on me was what got me going.

    Routers aren't that expensive. I got my Cudy for just $40. It did take a few hours to get switched over, mainly because I like to go through every setting before I consider the installation complete.

    Basically the steps are to go through the modem/router's UI and copy down anything you want to carry forward. Then you switch it to bridge mode, swap in the new router, and reboot the lot. Then it's just going through the router's UI to set everything up.

    There were lots of improvements. The big one was getting
    #WiFi7 and #WPA3, which has Perfect Forward Secrecy. That means that even your encrypted data can only be decrypted for a certain time before it becomes worthless. This is important when you realize that in the near future with quantum computing and such, everyone's encrypted data captured now will be trivial to crack.

    Another big improvement was the ability to force everyone to use DNS-over-HTTPS (
    #DoH). Not using DoH means your ISP can see every domain that you visit or even think about visiting. I went with Quad9, which is a Swiss DNS host, which focuses on privacy (duh, it's Swiss).

    The third big improvement was
    #mesh support. I was able to connect it with my access point via CAT7/8 cables and a switch for backbone. So now as I walk around the house, my devices move between the two access points.

    Don't forget to turn off
    #TR069 or your ISP will still have control over your router. I'm still working on how to get WiFi into my backyard.

    RE: https://mastodon.social/users/protonprivacy/statuses/116962426790206038

  3. A few days ago I left one of my Thinkcentre M910Q boxes sitting on top of my rack. It’ll be fine there until I install it. Out of the way… today in a rush to get to my physio appointment my shirt caught the box and sent it flying onto my TrueNAS.

    Remember folks, if you think at the time, “it’ll be safe, such and such can’t happen,” that is your future self whispering in your ear to NOT DO THAT!

    #homelab #doh

  4. 🚨 New blog post: When Privacy Tools Fight Each Other – IronFox, Mullvad DNS and Quad9

    In my latest article, I explain how I tracked down the problem, the online tools I used to verify it, why browser-level DNS can override system settings, and the simple change that solved everything.

    🔗 peakd.com/privacy/@rubenstorm/

    #Privacy #CyberSecurity #DNS #DoH #IronFox #Quad9 #Android #OpenSource #Freedom #DigitalNomad

  5. Oh, because the world definitely needed another convoluted #guide on setting up your own #DoH service, right? 🙄 As if your grandma's knitting club wasn't already running their own #DNS #solutions. 🧶🔧 Spoiler: Ctrl+C, Ctrl+V isn't quite the same as "setting up." 🤦‍♂️
    nochan.net/b/Internet-Crap/202 #setup #techhumor #CtrlC #CtrlV #HackerNews #ngated

  6. @[email protected]
    @[email protected]

    Hello,

    I would like to know whether, in RethinkDNS, the filter lists I subscribe to are still applied when I select DNS over HTTPS (DoH) with Quad9 as the DNS server.
    Does RethinkDNS add its own blocking on top of Quad9, or is only Quad9’s filtering used in that case?

    #RethinkDNS #Quad9 #DNSoverHTTPS #DoH #Privacy #Cybersecurity

  7. Soooooo, have a wild guess who has to high tail it to an nearby embassy, because they packed the leftover picnic into the same bag as where they stored their passport and then forgot all about it ...

    The leftover pate, melted in the hot sun, leaked and dripped into the plastic bag I store my passport in and stewed/soaked/marinated for two days.

    I can get a temp passport by Wednesday but since it's high season of people travelling and forgetting that their passport have an expiry date, where they last stored in a safe place or washed it in pate grease, it might take 3 weeks before I get a new passport.

    #YaNumpty #Idiot #Dumbass #Idiot #Doh

  8. NextDNS, AdGuard DNS, Cloudflare for Families, Pi-hole, мы — честное сравнение от конкурента

    Я делаю VantageDNS, recursive DNS-resolver с фильтрацией. То есть прямой конкурент всех, про кого пишу ниже. Это, мягко говоря, неудобный жанр: писать сравнение продуктов, в котором ты сам участвуешь, это как быть судьёй на матче своей же команды. Поэтому сразу два правила. Первое: свой продукт ставлю в самый конец, после всех. Второе: про себя пишу как сторонний инженер, без украшательства, и где я хуже, там пишу хуже. Если в финале вы почувствуете, что я всё-таки скатился в маркетинг, ругайте в комментариях, это будет справедливо. Мне реально интересно, как выглядит расклад в 2026 году, потому что юзеры регулярно пишут в саппорт «а почему не NextDNS» или «а что там с AdGuard». Хочу один раз ответить нормально.

    habr.com/ru/articles/1035660/

    #NextDNS #AdGuard_DNS #Cloudflare_1113 #Pihole #Control_D #DoH #сравнение #privacy #DNSпровайдер #adblocking

  9. @hugo @mullvadnet That is a very nice service ! Thanks for the tip. Was not aware of how cool was and its (I was after the same functions in my flake as a level 2/3 tool for also all url connections performed also by programs and CLI).

  10. @adingbatponder for anonymous #DNS providers, checkout @mullvadnet :

    Free #DNS servers with #DoT, #DoH and optional block lists. No need to be a paying customer.

    mullvad.net/en/help/dns-over-h


  11. example (yes, made with Claude Code) made to see how many hoops are needed to be jumped through to not even get remotely close to the privacy that provides over
    Reticulum is remarkable as compared with the info leaky internet infrastructure we use daily. github.com/DNSCrypt/dnscrypt-p

  12. Shocked that it has taken me so long, thanks to a heads-up from a friend & via , to see that I should have set up:
    (1) on my serving my sites
    (2) on my daily driver.
    url names (web addresses) are *not* by default even on sensible operating systems!
    The incessant leakage to & intermediaries of site names visited in 99.9% of cases is an egregious issue I never knew of. Using is next? All fixes rely on OMG

  13. Dear DNS admins, when you set up DNS over HTTPS on top of your resolvers, do you enable Basic Auth, apply allow by IP or limit access otherwise? :blobcat3c:

    #dns #doh #sysadmin

  14. @celenity I cannot seem to disable #DoH / #DNSoverHTTPS on the latest #IronFox release (not sure about before). Despite changing settings it ways shows a DoH server in use in about:networking#dns even after a fully restarting the app.

    Can you check that out?

    Edit: never mind. The cause was #grapheneOS adding new #VPN interfaces as "always on". 🙄 Ughhh, was almost going crazy.

  15. Doing some prep for next week and I'm kicking myself for not noticing what was going on here for the longest time:

    Find the largest prime factor of 3^15 + 3^11 + 3^6 + 1

    #mathpuzzle. #doh