I would setup my own Pi-Hole if I wanted true privacy.
Missing something?
I would setup my own Pi-Hole if I wanted true privacy.
Missing something?
""" To be fair, there are also some advantages of using Pi-hole® over NextDNS:
1) You know who runs it. We can’t ask you to trust us more than yourself. We can provide all the guarantees you want, show who we are and make promises, it is understandably easier to trust a solution you manage yourself. Keep in mind though, that all your unblocked DNS queries are still visible by your upstream DNS. So there is still someone you need to trust with your data.
2) It’s free with no limits. NextDNS is cheap, very cheap, but it’s still a paid service if you use it over a certain limit. Pi-hole® is free to use. You still have to pay about $35 for a Raspberry Pi + an SD card, which is equivalent to several years of NextDNS subscription. You should also consider donating to the Pi-hole® project if you use their solution. After a few years though, yes, Pi-hole® should become less expensive than NextDNS. """
They can't, but it might make sense to do so anyway.
I always explain this when it comes to running your own private CA as well. In principle you might do a better job than anybody else, and certainly if you fall down you'd know exactly who to blame. But you also might do a pretty shoddy job and cut corners you know you shouldn't, and knowing whose fault it is will be cold comfort if things do go wrong.
People who do this for a living can never be as trustworthy as you could be, but they might very well be more trustworthy than you are in practice and it's worth a moment's honest introspection to consider that.
The workflow I am (not quite finished) setting up is as follows - I run a caching, recursive nameserver (unbound) in my own colo space. That DNS server, not me or my devices, is the nextDNS client.
Then I set all of my own networks and devices to use my (unbound) DNS server.
My goal is to receive all of the benefits of a paid nextdns account, but on the nextdns side, all they see is a single, fixed IP, in a fixed location, owned by a corporate entity, doing a bunch of DNS queries.
In fact, I am a bit worried about this exact setup because although I am using this for my own, personal use, consistent with their expectations, I could just as easily be a full-blown ISP passing through my nameservice to nextDNS ... how do they deal with that ?
Do they care ?
I'm sure they can refuse service to customers in certain cases.
So I assume they allow (or, rather, can't really disallow) such a setup but I wonder what ramifications it has when someone decides to front their entire customer base behind their nextDNS acount ...
There is a valid niche between no privacy and completely self hosted dns-over https, that a service like nextdns solves well. Just as Apple solves a by default more secure yet still not without flaws phone, or how using a vpn provider is a midpoint between a self hosted vpn and no vpn. I think the privacy trade off here is good for many.
As always it's a matter of tradeoffs, if you just don't want to get tracked by ads it's probably a good solution. If you are afraid of some nation state trying to track you down, then probably not.
NextDNS can also be used as a fallback if your Pi goes down for whatever reason too. Might as well have options in this space.
For those of us with a raspberry pi or intel nuc on hand, sure, it only takes 30 minutes.
This service is for people who want to kill ads at the DNS level without dealing with the hardware / setup of pihole.
Also, not many people are going to bother setting up a VPN to access their pihole DNS when traveling or on cellular, which makes NextDNS attractive.
The other argument is "just use ublock matrix". The counter-argument is it doesn't block native app ads / tracking. (One of the #1 blocked domains on my pihole is from Dashlane's MacOS app, constantly wanting to phone home)
That seems pretty dismissive of our audience. I cant think of many things easier to set up than pi-hole, unless even using SSH is too difficult to understand.
1) Buy a rasp-pi (or pretty much any other device support a reasonably standard Linux distribution)
2) Copy one of many Linux distributions to an SD card with something like etcher: a couple clicks. Or buy one of the many pre-made kits with Linux already on the card.
3) Run a single line linux command via SSH and follow prompts.
Although I agree, it's not terribly complex to follow the steps. Lack of time to fiddle with self-managing a device seems like it could be a bigger limiter.
The "cloud players" you're worried of are big targets and the law protects me, since we have the GDPR and the EU is trigger happy in giving fines to big companies. Also my data is not that useful right now to a US company.
Also the ad blockers for iOS Safari don't work well and I use iOS Firefox anyway, which can't use Safari's content blockers. So I'll take any help in blocking ads I can get.
This will also be valuable for doing some content filtering for my son, without installing anti-virus crap on his devices.
It really depends on your threat model.