Essentially it's just DNS filtering on steriods. You start with an empty (or preseeded) ipset, and a firewall rule that says to reject/drop all outbound traffic if the destination isn't in the ipset. Dnsmasq is setup as the default dns provider in DHCP, and it's setup to add all resolved IPs to the ipset (with an expiration so stale entries get removed).
Then it's just DNS filtering per the usual. DoH, DoQUIC, DoT, etc don't work as their hardcoded IPs are blocked by default, and DNS filtering knocks out domain resolution of the endpoints. Even if an alternate resolver is allowed through the firewall, none of it's responses get into the ipset, so it's still broken (and is a sign I need to update the DNS filter).
Works a treat on my IoT devices
https://www.sidnlabs.nl/en/news-and-blogs/dns-resolution-req...
However, I'm more worried about when they start hardcoding DoH servers.
I can’t filter it or redirect it like I can with plain old DNS.
Many years ago I anticipated that "developers" would no longer allow end users to choose DNS servers. The developers' work, i.e., software, was dropping in market value and they began to adopt a Trojan Horse "business model". End users could use the software for free with the expectation that few would notice/complain about increased surveillance and data collection, or injected advertising.
The so-called "MITM proxy" is neither a new nor radical idea. Corporations routinely "MITM" TLS traffic from their networks. Enterprise hardware/software companies have provided turnkey solutions.
The issue is not limited to addresses for DNS servers. For example, WhatsApp hardcodes IP addresses in their mobile app. For that problem I use an application firewall.
The PiHole is essentially a slightly modified version of dnsmasq running on a RPi. It is funny that no one has tried using other DNS software. Given a choice of DNS software, I would not choose dnsmasq. It also still seems that no one has presented a "PiHole" that uses a forward proxy instead of a DHCP/DNS server. Similar to corporations, home users need a turnkey solution for monitoring their home networks.
You'd think thats thr job of the router companies - they sell you hex-core routers for $390 or whatecer, but no usefull functionality
TBH, I always found the Chromecast proposition to be unreasonable: "Look at this neat form factor single board computer you just paid for. Too bad only Google is allowed to have control over it. Sorry, you cannot use this for your own projects because [unspecified]. Google must be allowed to conduct surveilllance and gather data." By comparison, lack of complete control over the RPi GPU is rather easy to ignore. AFAIK, the RPi Foundation is not selling online ad services. Compare the number of cool projects people have done with the RPi versus the Chromecast.
1. I think it used to be possible to force use of different DNS servers via DHCP as well.
But if the network outright blocks random DNS requests, that only leaves DoH, which would require fixed IPs, which should be able to be detected and blocked, right?
Sure, the setup becomes a bit more involved...
This doesn’t work with DNS over https of course.
So you won’t necessarily even get to play this cat and mouse game - the dns requests are indistinguishable from your web requests.
I guess you could mitm your own ssl traffic and strip out dns answers there?
But then … how soon until we see DoHoH?
DoH over Tor already exists, but more importantly, Oblivious DoH (kind of like DoHoH) is being standardized by the IETF: https://datatracker.ietf.org/doc/draft-pauly-dprive-obliviou...
ODoH isn't going to be defeated by TLS MitM afaik.
This means that the DNS response for the web server would always be the proxy itself, or some set of proxies (and it would have to be the same IP for both wanted and unwanted traffic). What does DNS even add at that point? You'd be better off just making your "wanted" and "unwanted" servers the same server.
Few of these ideas can be expected to work unless Evil, LLC controls the program the end user chooses to read the web. When an advertsing services company is also the majority share "web browser" vendor, then ideas like this become feasible. Whereas if web users can choose any client to access the web,[FN1] then these ideas would be non-starters. The open source text-only browser I am using is not going to read the IP address of an ad server embedded in a web page and connect to it automatically. Even if it did, I would simply edit the source code to disable that behaviour and re-compile.
1. In theory they can but in practice they generally don't.
I guess, at this point, the other commenter's solution of "just stop using those things" may be the best.
> I guess, at this point, the other commenter's solution of "just stop using those things" may be the best.
Yeah. Assuming this doesn't change, this is the end result for me, at least.
The next step in the arms race is DoH. Afaik no one has a generic answer to that beyond "treat devices behaving hostilely as hostile".
> Nearly 70% of smart TVs and 46% of game consoles were found to contain hardcoded DNS settings - allowing them to simply ignore your local network’s DNS server entirely. On average, Smart TVs generate an average of 60 megabytes of outgoing Internet traffic per day, all the while bypassing tools like PiHole.
https://labzilla.io/blog/force-dns-pihole
For those devices which ignore DHCP/NDP provided DNS addresses, you could create a firewall to redirect outgoing port 53 traffic to your own server.
This is a big reason why I will never buy another Chromecast branded product, or Google product, again. Congratulations on successfully monetizing my time and annoying me into swearing off Google products altogether.
The DNS queries for these bypass any of your own DNS settings.
They even bypass host file overrides.
https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Cyber-Si...
For example, can you stream Netflix @ 4K via RasPi? I assume no, due to super strict DRM.
It is a little bit surprising to me that the big streaming companies have not creating an open source operating system (similar to Android) that can be used by manuf to create TVs. Then, smaller manuf can find ways to offer bloatware- / adware-free options. Maybe this already exists, and this comment makes no sense!
HDR and OLED are available in some monitor models, but to my knowledge there aren't any 55" monitors with HDR and OLED, and especially eARC.
https://docs.netgate.com/pfsense/en/latest/recipes/dns-redir...
If the dns request is over 443 and the DoH server is the same host as the served resource, what can be done ?
The next step in the arms race would then be to implement DoHoH.
Sigh.
Now what ?
Not sure what potential issues are are being mentioned here, but I'd say a separate VLAN for IoT devices + QoS [0] should rule out most of the concerns.
If it's running on Win/Mac/Linux/Android/iOS, block the app from talking to the gateway, or even the entire LAN.
In my opinion, additional being a curios software engineer I find it quite interesting.
Necessary? Perhaps not but helpful.
Heating valves for example.
The definition of iot from Wikipedia also does it.
But honestly why I hate my iot window blinds device it's the perfect excuse to use vlan at home.