OpenWRT will natively support NextDNS in upcoming 19.07.0 release
github.com
github.com
Release notes: https://forum.openwrt.org/t/openwrt-19-07-0-first-release-ca...
1. OpenWRT for the most flexibility but you have to edit config files for the more obscure stuff. Tends to take more memory/CPU than others and tends not to run well on older hardware. An entire platform.
2. DD-WRT for the most features available from the web interface. Older versions are suggested for older hardware but that might have security implications.
3. Tomato for the easiest and nicest web configuration interface. Does not support as wide a range of hardware as the others. Might also have issues with older hardware for more obscure features.
Tomato hasn't had a stable release in 9 years.
OPEN-WRT is a fork of DD-WRT. Lede was a fork of OPEN-WRT, but has remerged with OPEN-WRT. OPEN-WRT is the best firmware for home routers/access points in my opinion.
It used to be that dd-wrt was less open than openwrt, but worked better. I think now, though, openwrt has surpassed dd-wrt.
If you have the luxury of buying new hardware, I would go the OpenWRT route but just make sure you read EVERYTHING on the hardware support page before pulling the trigger. If you're trying to convert an existing router, definitely do research on both, there are advantages to each. Personally if I had a router supported fully by both, I'd go OpenWRT at this point.
I don't know that there is one.
My experience these days when I install a new wifi router is wading through pages and pages of forum posts to try and identify the firmware (or particular build thereof) that will work best on the particular hardware I am configuring that day.
Usually, after a few hours of digging, I sort of "converge" on a particular firmware and a particular release.
Then it's on to experimenting if the thing actually works. If it doesn't, rinse and repeat.
This is very frustrating, and for a number of reasons:
- From a security perspective, you end up installing a random unvetted piece of binary software on what is basically the gate holding the fort secure.
- You operate on hearsay (forum posts)
- There is no guarantee the process will converge.No more of that. Today, buy a router OpenWrt supports and just install the official images and get on with your life.
The days of a $50 router in the home having great software seem to be over.
The next major release of pfSense will require hardware encryption support (e.g., AES-NI).
OPNSense is very reliable, but has fewer features though is in active development. Haven't used it in around 18 months or so.
I picked up an HP 4-port 1gbps PCIe card for $40.
Ever do a tiny load of laundry to get one shirt clean? You've just used something like a year of computer running.
Do you run your air conditioning while your refrigerator exhausts into your kitchen? I call that a kitchen heater. You're heating a cooled space.
I find for whatever reason, tech people all worry about the energy consumed by tiny devices.
Another thing to keep in mind if you're worried about power/heat is that 3.5" spinning rust can pull >5 watts per spindle. I've seen 15K drives pull close to 20. But an SSD is close to nothing and so are most 2.5" laptop spindles.
OWE = Opportunistic Wireless Encryption, previously if your WiFi has no password everybody can passively snoop all the packets, so it makes sense to use a password even if you tell everybody what it is, like FreeWiFiHere - so that an active attack would be needed to steal data and you've some chance to detect it. OWE says wait, why not use ephemeral keys even if there's no password and then you only set a password if you actually wanted to deny access to people who don't know the shared password.
With the common ‘social-graph trackers’ apps list tab, toggling WhatsApp if you have to text with a European or Instagram if you want to post is easy, for instance.
Or, leverage the NextDNS app, and use the giant toggle button.
>Get in-depth analytics about your Internet traffic.
>Shield your kids from adult content.
Do you use NextDNS as a way to monitor your children online?
I would imagine the performance of settings it on pihole would be unnoticeable, as it also stores blacklist in memory. The only latency difference would be in network request likely.
Most routers are not powerful enough to efficiently run blocklists and analytics locally.
I should definitely do some benchmarks though. There are occasional times where I feel like DNS lookups take significantly longer than normal but that’s once in a blue moon.
This dns may be a good option for the non-technical but personally I never want a DNS to do filtering for me.