Maza – Like Pi-hole but local and using your operating system
github.com
github.com
You can use it as-is but if you want user-specific configuration you'll get a custom URL that looks something like "https://dns.nextdns.io/c8g88a", and whatever comes in that way will use your settings and will be logged as per your configuration (of course, you can disable logging).
I set up dual redundant pi-holes on raspberry pi 4s on my home network but switching all devices to NextDNS would give me access to filtered DNS even when away from home, plus save me the trouble of running two raspis (including two Ubuntu instances) just for that purpose.
Could anyone knowledgeable in such things suggest any downsides to a wholesale switch?
NextDNS Pros:
* Can use NextDNS on any network (thanks to their apps or just regular DNS-over-HTTP/TLS).
* (Could get similar functionality on PiHole with a remote hosted PiHole + VPN, but much more complex to setup)
* NextDNS allows for multiple different configuration setups per account (so you can fine-tune your blocking/filtering differently for different devices).
* (PiHole AFIK only supports a single configuration)
* NextDNS IMHO had the superior UI. With more powerful config options.
* In reality with some extra manual config/coding you could probably get PiHole to do most of what is in the config for NextDNS, but it would take some work.
PiHole Pros:
* PiHole is open source.
* The NextDNS server code is closed-source, but they do have an open-source CLI client.
* PiHole is self-hosted (much better from a privacy perspective).
* But you do get all the downsides of being responsible for hosting something as central as a DNS server yourself...+Pihole is free and open. It is also yours to build,manage,customize as you please.
-NextDNS is also further away, meaning there will be much more latency for all your DNS queries. It is usually best to run your own resolver, or have a local DNS server in your network.
+Pihole sits on a device on your network. You can also enable recursion directly on the pihole by installing Unbound on the same device.
But your local PI resolver would likely have to pass on your request to an upstream DNS server if it isn't cached. Although its negligible, this extra hop would add latency. This is assuming the result isn't in the OS or browser DNS cache.
There are tons of important details to keeping a critical service up and running almost all the time - even if you are competent in this, that is still time every month making sure it's running, secure and functional.
The only reasons in my opinion to DIY a solution would be a) learning, hobby or for fun or b) you have requirements that can't be met another way, like privacy goals.
Running NextDNS has costs. Given the absence of fees for using NextDNS, it has a commercial interest in collecting information about users. Like other third party DNS providers (middlemen), e.g., Google or Cisco/OpenDNS, NextDNS supports ENDS Client-Subnet. This extension has zero value in terms of ad-blocking and privacy and arguably should be "off" by default unless the user asks for it.
PiHole is non-commercial project AFAIK, although they have registered a trademark.
Third party DNS caches will always be inferior to DIY in respect of certain issues such as ad-blocking, privacy, security, reliablity, etc. (I am a DIY-er and when third party DNS has an outage, the applications I use are still able to use the internet without any problems because I have zero reliance of third party DNS providers.) When using third party DNS these factors are outside the user's control. Users cannot tell third party DNS providers what to do, nor can they execute quality control, they can only accept what is offered to them. Of course, third party DNS will always be superior in terms of convenience and perhaps "features". I personally do not need all of the "features" offered by third party DNS, but I cannot speak for other users.
The user's "choice" between DIY and third party DNS depends on what is important to the user and what the user is capable of doing herself. When the user is not capable of running DNS software herself, then DIY is removed from consideration and the "choice" is simply between one third party provider or another. The user has very little control in that situation.
When it comes to DNS, for me nothing beats having control. For me, "control", not convenience, is the best feature. I prefer whitelist to blocklist. Every user is different.
Having said that it's free (beta) right now so that's a statement of fact and by no means a complaint
The only issue's I've had is:
1. Epic Game Store was blocked - not an issue now as I uninstalled it and bought Borderlands 3 on steam. Now EGS is blocked again.
2. Adverts display in Google now that I don't have an ad-block, but it prevents me clicking them so I'm not fussed.
3. raygun.io is blocked - not sure why as it doesn't track any information of value as it's primarily used for crash reporting, and they are GDPR compliant.
Other than that, this has been amazing. I'm definitely going to be a paid customer once its out of beta.
adguard pro allows customization of dns servers (including DoT), has a running local log of dns queries, and provides custom whitelists/blacklists functionality. their dns (or maybe the app) very occasionally hangs requests, making my device seem like it's disconnected.
i've considered switching to nextdns but haven't found a compelling reason yet.
I've been using it too, but I've found nextdns go down from time to time. How are you dealing with explaining how to change the DNS setting to people at home because "internet doesn't work"? I wish DoH client implementations had support for primary and secondary endpoints [0]. I've seen people straight up uninstall DoH clients from their devices in frustration.
I must point out that the Android implementation for DoT does fallback to OS or network provided DNS resolver (usually, dns.google), and that's a saving grace [1]. And so, I have no reservations setting up nextdns for everyone on the Androids.
Fwiw, I've found running DoH with Stackpath Edge Engine and Cloudflare Workers to be quite trouble-free, but it isn't for everyone: https://news.ycombinator.com/item?id=22414433
---
[0] Nebulo (https://play.google.com/store/apps/details?id=com.frostnerd....) is the only Android DoH client I've seen support this.
[1] Speaking of DoH instead: Google's https://getintra.org falls back to last-known good DoH resolver, but then, never (?) switches back to primary unless restarted, from what I can recall.
I may be mistaken here but I thought the reason almost all operating systems allow you to specify more than one DNS is in case the primary one goes down. So if you specify NextDNS as the primary and say, Google or whatever, as the secondary: you likely won't see downtime (but obviously the filtering will disappear until the primary one comes back up and/or DNS caches reset etc)
For example, my default Kubuntu 19.10 installation flips the primary and secondary if the primary is unresponsive for a while. Since my laptop takes a moment to establish a WiFi connection upon waking up, it always decides that the primary server is down and to default to the secondary server. It has currently been 3½ hours since my laptop queried its primary server and it has queried the secondary server over 1000 times in the past 24 hours despite the primary having 100% uptime.
Most stub resolvers have an option to use strict order, but you can't rely on it as a network admin.
Android 9 and later natively supports "Private DNS" which is DNS over TLS.
All work fine with NextDNS and I have multiple profiles for each hardware I use it on. Eg, I use more block lists on my phone than my other devices.
I'm using https://github.com/dimkr/nss-tls with https://github.com/dimkr/dohli on Linux and it works well. Everything, not just the browser, uses DoH and with endless customization, since I own the server.
If you're using a computer on which installing this software is an alternative, you can install a web browser with an ad blocker, which performs much better than DNS based filters.
If you're not using such a computer, Pi-Hole proves DNS filtering and this software doesn't.
What's the use-case between these two that isn't already covered?
I still don't get it.
Think of it like a DNS-layer firewall. Plenty ways to get circumvent it, but works wonderfully, nonetheless.
> in the case I saw it was sudo
This isn't an all-in-one security product. Just one way to firewall trackers, ads, and whatever else one wants.
It's not a broad use case but it's also really cheap to do and doesn't have a lot of maintenance cost.
People who want to learn and/or want something simple. This version is super simple with the whole application being a ~150 line shell script. This makes it very easy to understand and adapt.
Eg. I have a file-server that runs our DHCP and DNS. I've looked into using Pi-hole's setup on it before and it just wasn't worth the trouble due to mismatches between their setup and mine. OTOH this version is very easy to understand and tweak to my needs (eg. using unbound vs. dnsmasq).
This is a good workaround for that use case.
- uncomment this in your dnsmasq.conf:
addn-hosts=/etc/banner_add_hosts
- put this in a file in /etc/cron.daily: wget -O /etc/banner_add_hosts 'https://pgl.yoyo.org/adservers/serverlist.php?showintro=0&mimetype=plaintext'1.setup your docker-compose.yml file with the one listed on pihole page https://hub.docker.com/r/pihole/pihole/ (starts with version: '3').
2. save and do "docker-compose up -d"
3. do "docker ps" and ensure your pihole is running.
4. Go to network settings and set your DNS to 127.0.0.1 and ::1 like this: https://mayakron.altervista.org/wikibase/show.php?id=Acrylic...
5. if the docker container is ever stopped, you will need to reverse the setup step 4 to get back internet.
Hope that helps all you windows users who want a DNS blocker pihole on your machines!
couldn't run pihole network wide because too many shady "deal /discount" sites my girlfriend uses kept breaking, so this was my alternative.
Also set it on a colleague's phone and he's thanked me severally for it.
* (dns.adguard.com
private DNS in network settings on android pie)
See: https://nextdns.io/
DoT is very easy to self host if you already run something like a pihole (using nginx to proxy a tcpstream + having it wrap a TLS connection around it) and can be exposed to the internet because it can work over TCP (thus reducing the DDoS risk factor significantly).
In Android there's a setting to enable it in the network settings. The default will be "off", if you pick "on" you'll probably be using Google's DNS servers, if you pick "hostname" you can pick a different server.
Google support page explation for private DNS doesn't explain anything. Just recommends leaving it on.
iOS does support that.
Many DNS servers don't support DoT and some support DoH (DNS over HTTPS) instead.
Browser > Ublock
Local System > hosts-file
Android (root) > Adaway (does hosts-file)
I haven't tried it myself yet, but I've heard that NextDNS is the way to go on iOS.
For use on a desktop in a network you do not control (e.g. many devs have complete local control over their own machine)
I VPN to my home (and by extension my Pi-hole server) when on that kind of network. A local ad-blocker doesn't prevent MITM or malicious DNS servers. Maza won't help if DHCP is handing out the IP for a server that claims google.com is a CNAME to hereisyourvirus.xyz or if the router is transparently redirecting DNS traffic so you don't even know what DNS server you are hitting. Which means you have to use DoH or DoT as well.
This took me ages to find the cause of, I had to use a lot of highly-escalated debuggers and such to figure out what the "system" process was trying to do that was costing so much time. Once I cleared out the hosts file, the problem was resolved.
It's over 1.4mb.
And after any edit to the host file, it'd take minutes before I could browse. (Hard drive)
When I switched to SSD, the delay dropped to less than a minute.
For domains I already visited, cached, there were no perceptible resolution delays.
With it, I would simply switch to one of the many pi-holed/filtered DOH services[0] out there, or even roll my own on a cheap VPS.
On iOS there is DNSCloak which is excellent, Android 9+ has built-in support (Private DNS).
[0]: like pi-dns.com or blahdns.com
It also has an option to force all DNS traffic (port 53, so again it won't catch DoH/DoT) to go through the router. Occasionally I forget I've done this and tried `dig foo.bar @1.1.1.1` and gotten confused until I remember that my router is forcing that DNS lookup to go through it first, and then through the router's configured DNS resolver.
These are layers of protection from undesired content (ads, malware, porn, etc.). If one fails, hopefully the next layer will provide desired protection.
I have kids approaching teen years. There is no magic bullet, and we still monitor and limit their screen time.
How would you improve this setup? Just curious.
It could help fund future development and maintrnance costs.
Anyway, it's free software. Anyone in the world can do that if they want. You can do that.
Also, it's poorly scoped. Pihole is just an app. Any ownclowd provider can more efficiently host it along with a bundle of every other app people want to "own" but not run locally.
I think the GP's suggestion is a fantastic one!
You can even find comments about it on this thread
dnsmasq -> pihole -> stubby
The first dnsmasq is for local .test domains for dev. Works well for when i'm not on one of my networks.
On the go is the key here.
Not sure why the readme tries to obscure that.
I don't think it does, dnsmasq is optional. It does configure dnsmasq regardless, but that configuration only applies if you install and enable dnsmasq. As far as I can see, the script does none of that nor does it change /etc/resolv.conf. The readme is very clear about needing dnsmasq for wildcard blocking.
The script also modifies the host file which will apply regardless.