Show HN: nextdns.io – A Combination of Cloudflare DNS and Pi-Hole
nextdns.io
nextdns.io
A few suggestions:
- Auto-detect OS and suggest specific setup instructions right on the landing page?
- The website goes blank when I block third-party JavaScript from loading. Can you please see if you can fix that?
- simplednscrypt has been handy for me to DoT/DoH/DNSCrypt with AdGuard DNS on PC. You could include instructions in the Windows section for that? https://dnscrypt.info/implementations/
- Provide a generic DNS endpoint like AdGuard does?
A few questions:
- What's the backend that fronts DoH, DoT, and DNSCrypt queries? Is it simply relayed to Cloudflare underneath the covers? How do you do that?
- Re: Privacy Policy: "We store user data following modern security standards". What user data is stored using what modern standards? I like the terse policy document, but I feel there needs to be a fine print detailing data collection and data retention. Examples: https://s3.amazonaws.com/lantern/LanternPrivacyPolicy.pdf and https://info.ecosia.org/privacy
Thanks.
> Auto-detect OS and suggest specific setup instructions right on the landing page?
It should already pre-select your OS tab on my.nextdns.io on the Setup page? If that's not the case, then it's probably a bug.
> The website goes blank when I block third-party JavaScript from loading. Can you please see if you can fix that?
Weird, we will have a look.
> simplednscrypt has been handy for me to DoT/DoH/DNSCrypt with AdGuard DNS on PC. You could include instructions in the Windows section for that? https://dnscrypt.info/implementations/
You can use your custom sdns:// endpoint listed on the Setup page, we assumed users using dnscrypt clients would know what this means. Good point, we will add setup instructions for it.
> Provide a generic DNS endpoint like AdGuard does?
We already have them, we decided to not show them on the website as it may confuse users. We may add them back.
> What's the backend that fronts DoH, DoT, and DNSCrypt queries? Is it simply relayed to Cloudflare underneath the covers? How do you do that?
It's a custom-made backend, and we recurse using unbound (we don't forward to cloudflare or anything like that).
> Re: Privacy Policy: "We store user data following modern security standards". What user data is stored using what modern standards? I like the terse policy document, but I feel there needs to be a fine print detailing data collection and data retention.
We will definitely improve that, we had to make some calls on priorities for the launch.
Weird, we will have a look.
For those that block JavaScript by default, it would also be nice to get something more than You need to enable JavaScript to run this app. on the main page. At least a short blurb what this is.
(Since the most recent batch of CPU vulnerabilities, I have decided to use uMatrix to block anything but CSS by default.)
What's "weird" is that someone thought to mandate third-party map and chat javascript widgets on what should have been a simple page explaining what the combination of Cloudflare and PiHole is.
Running your own private recursive resolver is very easy.
Edit: I believe people are confusing running a DNS nameserver with running a DNS resolver. The former might be hard, the latter is very easy.
If you run e.g. Linux or BSD, you'd just install knot-resolver, enable the service and put "127.0.0.1" in your /etc/resolv.conf. That's it.
Similarly if you run something like pihole it is very easy to have it run a recursive resolver as well, I bet pihole has a page on how to set that up, and I doubt it is hard in any way.
If, of course, all you have now is a router provided by your ISP and you want to run your own intranet DNS resolver, then, yeah, you'll probably need some hardware for that. Obviously.
[+] some networks hijack outgoing DNS.
Implementing the whole thing (modulo the anycast IP, which is the only thing I did not use) is easy. I have a docker-compose file which does the whole stack:
1. Unbound DNS which provides DNS-over-TLS service at port 853. It forward request to my local pihole's 53 port. 2. Pihole forward request to my Stubby DNS server. 3. Stubby connects to Google DNS over DNS-over-TLS. 4. A separate docker container to run certbot to update certificate used by the unbound container. 5. A separate docker container with Pomerium as reverse proxy so I can remote access PiHole UI.
Then you can configure your Android phone to use your unbound DNS server as the "private DNS" server. I've being using this setup for more than a month and works really well.
UPDATE: I posted my docker-compose.yaml file at https://github.com/yegle/your-dns. I'll update the README soon.
This project seems to occupy the same niche as products like Blokada. Most of the benefits of a self hosted solution, with a much lower barrier to entry.
Even with this setup there are ways to increase reliability with-in the budget/skill set of a normal engineer, e.g. run two RasPi with keepalived and run VRRP on your routers. As a last resort, I can disable the "Private DNS" setting on my phone if my DNS is down and I can't fix quickly enough remotely.
From a networking perspective, getting VRRP working on anything but physical equipment (e.g. in the cloud) is a fool's errand; it's L7/API-based and not on the ethernet level. Similarly with keepalived, which will get isolated from the monitored instances (thereby failing to the other, also "down" instance) — except it might have access to the API gateway of the cloud provider thereby disassociating the V-IP from both your instances; so you'll end up with more downtime with keepalived than you gain by it.
Since DNS is by default inconsistent, but eventually consistent and thereby possible to load-balance, you could run one instance of this stack on your static home IP and another instance on GCP/DO/AWS and configure multiple DNS servers in your DHCP options and on your phone, to get higher availability.
Look, I'm not trying to sell my solution here. This is Hacker News, I'm simply share my setup and hope can help someone who's capable and willing to invest the time. I understand this is not for everyone, that's why I suggest nextdns.io as hosted solution in the README.
That sounds like a pretty good reason not to run your own solution then, so I guess we can meet there.
> Look, I'm not trying to sell my solution here.
Yes, you are.
The most useful option I've seen for trying to get the benefits of both has been rotating between a list of DoT resolvers, so none get all the history and end up with fragmented profiles. There's issues there since people access the same services and thus they'll get the full list over time if the software doesn't record who got what request and stickies it to them. There's always the option of doing it over Tor, but then you're introducing multisecond latencies to your DNS queries, which isn't exactly a great experience.
So because a snooping provider is irrelevant when we talk only about resolving DNS, that only leaves the choice of which party to the chain of entities that are able to easily snoop on your or not. If privacy is important, adding Google or any other DoT resolver to that chain is strange.
Second, Google uses personal data combined with machine learning to optimize "user engagement" (roughly, hours spent on the service) because that has been proven to be a good predictor for how resistant an internet service is to competition or disruption. This optimization of user engagement has a bad effect on the productivity and perhaps the mental health of individuals and families and has a bad effect on our public discourse.
Well done.
Docker compose file makes everything easily reproducible and I've included working example configs. Not sure how I can further simplify the setup but open to suggestions.
Here is a few things you can do with it:
- Block malicious websites, trackers, ads, and more by combining the most popular blocklists out there, all updated in real-time (100+ lists to choose from).
- Set your own privacy requirements: you decide what type of logs are kept (and for how long) depending on the level of analytics you want. Down to absolutely NO logs.
- Automatically use DNS-over-HTTPS on all networks (including cellular) with our apps for Android, iOS, Windows and macOS. They are all tiny, tightly integrated with the OS and have negligible battery usage. (Some of them are still being worked on.)
- Bypass nearly all forms of government/ISP censorship without the need for a slow/costly VPN, and make it way harder for your ISP to know what you are doing on the Internet.
- Get in-depth analytics and real-time query logs so you can measure the efficiency of your blocking strategy, see when the apps on your devices are calling home, etc. And choose what is logged down to absolutely no logs, you decide.
- Easily protect your family (you can create as many configurations as you want on one account, each with different settings, and you can use multiple different configurations while being on the same network).
It also supports all the latest DNS technologies (DNS-over-HTTPS/TLS, Query Name Minimisation, DNSSEC validation, etc.), and it's fast (for most countries, we are or will very soon be as low-latency as Google DNS, Cloudflare and the likes).
There are tons of other cool stuff we built into that service (like the fact that each configuration gets its own DoH/DoT endpoint and IPv6) but that post is already way too long :)
We recorded a short GIF of us browsing through the interface: https://gfycat.com/LinedVerifiableBellfrog
You can create your first configuration and test it right away without signing up (you can sign up later and "save" it).
We would really appreciate if you could try the service, tell us what you like, what you don't like, what you would add, etc. We will happily answer all questions (even the technical ones).
Cheers, and thanks!
See also: Netlify.
Best of luck! Looks great.
This looks really cool. I'm nervous about entrusting someone with stuff as sensitive as DNS. If this is all it appears to be, I may be a paying customer (tho I try to only use/pay for free-as-in-speech software).
I would like to see more software adopt this model. Can you give a few examples of things you support? Are they all pay-for-hosting services, or are there cases where the software itself is for sale?
A strict interpretation would suggest something along the lines of "we don't censor what the customers of our software do with it", which is true for almost all software (aside from social media platforms). I don't see how this would apply here, since this software isn't being used for the creation of anything.
A looser interpretation would suggest that, if the software is used to access content (eg. web browser) then, aside from technical limitations, it doesn't censor content that it could otherwise display. I can see how this might apply to a DNS.
I don't see, however, how "free-as-in-speech" has any reference to open or closed source. (Not sure if that was what was meant.)
The most recent example would be FileBot which I bought a subscription for mostly because it is high quality and is free software (as-in-speech). I would have used less functional free (as in speech and beer) alternatives had the filebot source not been available to me.
Filebot homepage: https://www.filebot.net/ Source code: https://github.com/filebot/filebot
Edit: Actually, it's worth noting that the statement in the README arguably makes filebot non-free. "You may NOT use the source code to publish binary builds without explicit authorization." If that's actually supposed to be enforced by the terms of the license, filebot is definitely not libre software.
On the other hand, it's not clear at all whether this is prohibited by the license. It prohibits "Publishing binaries or competing clones that undermine the ability of the original author to make money from his work." I don't see why publishing a binary for free on a new platform would undermine this in most cases, given that the author already publishes free binaries for most platforms on the official website.
That said I just tried to build it for the first time (wanted to make a small improvement) and there are no documented build steps and a standard ant build doesn't work. There are open github issues where the author is very dismissive and just says basically "code not supported, just for educational purposes."
I poked at it for about 15 minutes but I've never used ant before and couldn't get the build working. That really saddens me. Unless things improve I won't be renewing my subscription. I'm pretty disappointed to say the least.
> free-as-in-speech (where you can easily recreate the speech yourself)
Freedom of speech has nothing to do with recreating the speech. The term "free speech" means "no censorship".
The connection, as I now understand it based on other comments here, is that "free speech" refers to a freedom relating to people's rights as opposed to "free beer", which refers to cost. In that sense I can understand the connection to free software in the sense that Stallman advocates for.
2. How effective is it at blocking apps?
3. Will you OpenSource it?
4. Can you add some kind of Bash/scripts to configure profiles/settings on OpenSource routers such as OpenWRT, etc?
5. Will there be an API to control settings?
Should I assume you've gotten a huge spike in traffic because of this HN post? If yes, I don't mind trying again in a few days, but unless things improve, I wouldn't be able to use it despite loving it in concept (the UI of your implementation is great too). I don't want to discourage you folks, since you've done a great job with the rest of it.
Thanks for your efforts.
I am from Sri Lanka and I get following over IPv6 using dig,
80-120ms for Nextdns (92ms avg ping)
75-140ms for Google (61ms avg ping)
70-90ms for Cloudflare (75ms avg ping)
- a routing imperfection (this things need to be tweaked over time).
- the fact that we didn't deploy our PoP in India yet (coming this month).
Can you talk to us on the chat if you have some time? It would help to do some debugging.
In NYC on the largest metro ISP. Earlier in the day, was getting 25-43 msec to the typical major DNS providers (1.1.1.1, 4.4.4.4, 8.8.8.8, 9.9.9.9, as well as AdGuard), and usually 71 - 73 msec to you.
After a while, started getting as slow as 280 msec to you.
Last hour or so, mostly just getting timeouts to you, making the web, as well as apps, unusable.
Had to revert.
AdGuard DNS:
dig @176.103.130.130 news.ycombinator.com
; <<>> DiG 9.10.6 <<>> @176.103.130.130 news.ycombinator.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6879
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;news.ycombinator.com. IN A
;; ANSWER SECTION:
news.ycombinator.com. 56 IN A 209.216.230.240
;; Query time: 29 msec
;; SERVER: 176.103.130.130#53(176.103.130.130)
;; WHEN: Sun May 26 15:32:11 EDT 2019
;; MSG SIZE rcvd: 85
nextdns.io dig @5.182.208.100 news.ycombinator.com
; <<>> DiG 9.10.6 <<>> @5.182.208.100 news.ycombinator.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 14810
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;news.ycombinator.com. IN A
;; ANSWER SECTION:
news.ycombinator.com. 0 IN A 209.216.230.240
;; Query time: 282 msec
;; SERVER: 5.182.208.100#53(5.182.208.100)
;; WHEN: Sun May 26 15:32:17 EDT 2019
;; MSG SIZE rcvd: 85India is difficult. I run our anycast network and we have coverage in India but I look forward to improved routing there in the future with additional transit providers.
It seems nextdns is announcing exclusively with Vultr: https://bgp.he.net/net/5.182.208.0/24
Which is not in India: https://www.vultr.com/locations/
dig @5.182.208.203 google.com ;; Query time: 390 msec
9ms on Cloudflare, 10ms on Google.
Looking at mtr I'm occasionally routed to Dallas, Texas. Other times it's correctly routing over my ISP's peering to Vultr.
Or just a normal report, then lookup the IP location?
you solved it.
only turn down : mi iphone SE ( os last versions) seems to get little pics of heat
Funding: Free during beta, then freemium with low pricing tiers (something like free up to 500,000 DNS queries a month, then $0.99/month). We will tweak later based on actual costs at scale, but it will follow this logic.
Nextdns is blocking somewhere in the region of 400-600 queries each day, mostly things like Google Analytics, Apple iAd.
138,473 queries over the last 30 days
31,928 queries blocked (23%)
Hope this helps.
Something to ponder.
I know my Nvidia shield DRILLS Netflix even when it's a asleep.
Awesome!
https://en.wikipedia.org/wiki/Recep_Tayyip_Erdo%C4%9Fan#Elec...
And forget about reading up on the faux coup d'état.
https://en.wikipedia.org/wiki/2016_Turkish_coup_d%27%C3%A9ta...
I used to run something like PiHole on my home network but ultimately dnsmasq is not a good DNS server so I ditched it. I've been running CoreDNS for a while, forwarding to Google DNS and Cloudflare DNS (both using DNS over TLS) for a while and that worked fine. I'd augmented CoreDNS to serve a hosts file as a blocklist, similar to PiHole.
Nextdns has replaced Google and Cloudflare as forwarders in CoreDNS and it's working really well. I've been liking the proper network-level ad-blocking and being able to use the analytics to figure out what was blocked when something doesn't work.
The nextdns guys are also really responsive and helpful. One of them spent a couple of hours on live-chat with me debugging an analytics issue.
Every DNS expert I know says to avoid dnsmasq.
It works fine as a DHCP server, though.
But...
Why do you need a shitton of javascript to load your main page?
I cannot see the main page with ublock origin + umatrix blocking 3rd party and firefox finger print resistant options turned on.
Your setup page is fantastic! Especially appreciate the status indicating if it is set up correctly on the device I am using. I set it up on Linux, which I notice you don't have a tab for, but that should be pretty straightforward to add. (Even though Linux users may, typically, know how to do this themselves, it might be nice to include Linux as a signal that it is truly cross-platform.)
I noticed inconsistent results on Android depending on whether I had it set up via Intra or as DNS-over-TLS in the native Android settings. Internet browsing was similar to on desktop, either way, but my concern is mostly related to video apps, specifically the ones my family use (Hulu, YouTube, CWSeed). On Intra, all the video apps seemed to work but there were still ads in all of them. For DNS-over-TLS CWSeed stopped working entirely, saying "video playback failed". Hulu and YouTube still worked but they also still had ads, while on Desktop they did not!
These are the sort of issues I was concerned about when considering using PiHole for the whole house. Are these things that can be mitigated on your end, or will they require per-device apps to be installed, and potentially even require rooting the device?
(Incidentally, how is it that YouTube and Hulu get around the ad blocker on Android?)
Adding to the domain whitelist and/or disabling the DNS blocking temporarily (in case of issues) is dead simple for anyone in the family. You just need to provide them with the local IP address of your Pi. The GUI - at least for these simple tasks - is quite straight forward.
I agree though, this service looks very promising.
I think it happens after you configure an anonymous DNS, then you create an account. It feels like my configuration got disconnected or something. Hard to describe.
Regardless, the blacklist/whitelist didn't work. Maybe a caching problem? Will try back later.
1) Consider launching an App for managing configurations or at least make the current web app a PWA
2) Allow users to create duplicate configurations
3) In the logs section of the analytics page, I saw that some blocked domains were being resolved, it was saying that the domains were manually whitelisted(they were not)
4) Allow adding custom hosts file sources
5) You can create a Windows/MacOS app for updating dynamic IP address(similar to the one provided by OpenDNS)
6) You can give a button to whitelist domains in the log section, just like the one provided by the PiHole in the Query page of its web UI
7) Allow adding multiple domains to whitelist & blacklist at once
8) Allow regex and wildcard blocking
9) Mobile UI is not 100% responsive
The privacy policy [0] also shines: it's five points and very specific.
I believe your service would also solves this problem. Congrats on the launch too!
Great job - I'd love to know if you plan on charging for this.
Free during beta, then freemium with low pricing tiers (something like free up to 500,000 DNS queries a month, then $0.99/month). We will tweak later based on actual costs at scale, but it will follow this logic.
Has anyone else seen this?
The tagline on the site is actually 'we like to think of it as ^...'
Per comments here I don't think it actually uses CF or Pi-Hole, so the title's a bit off.
Selling data is against what we believe in and would also be counter-productive (everybody would stop using the service instantly).
But has to be rock solid, and fast.
Clicking this link in iOS will work though, for some reason: https://testflight.apple.com/join/AFDFPLP3
How to remove them ?
> Free during beta, then freemium with low pricing tiers (something like free up to 500,000 DNS queries a month, then $0.99/month). We will tweak later based on actual costs at scale, but it will follow this logic.
But yes, NextDNS should provide something that's ready to copy-and-paste.
I’m not sure why you bring this up on every post vaguely related to pi-hole.
The “be advised” is just that.
It’s not a big deal, and I think I only mentioned it once before.