Technitium DNS Server: Self host a DNS server for privacy and security
technitium.com
technitium.com
So, if I have an internal record, record.example.com @ 192.168.1.2, I can query the server to ask "Hey, who is at 192.168.1.2?" and the server would reply with "record.example.com". This works by creating not only the example.com zone, but also a "1.168.192.in-addr.arpa" zone with the proper mappings. Technitium server will ask you to create the zone if it doesn't already exist when you create an A record for a zone.
https://knowledge.digicert.com/constellix/standard-dns/rever...
Do you mind elaborating on what this means real world in terms of what that allows you to do?
Using Technitium on your local network is like rolling your own Route 53 management console internally. I hate to use that comparison, but I think that'll hit more for some users on HN! If you need that kind of fine grained control, or if you just don't want your hand held on DNS, that is why you would choose this over PiHole.
Thank you to the Technitium team for giving us such a great product! Even if your name is hard to spell.
(Had to remove the slash to pass through cloudflare block)
Granted, you still have to install OpenWRT, but I still think that running a root DNS isn't necessary for home setups.
[1] https://blog.technitium.com/2021/07/running-root-server-loca...
I was going to write: You can’t write a comment with the text / etc / hosts?!
But I tried it and got the CloudFlare block page. That’s pretty incredible that a tech focused forum blocks you for simply referencing a common file on all Unix file systems. What state a sad future we live in.
Works for one computer, doesn’t scale.
Edit: another option allows for serving expired TTLs, which is permitted by rfc. There is a great explanation on their site [2]
[1] https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound...
[2] https://unbound.docs.nlnetlabs.nl/en/latest/topics/core/serv...
https://jpgpi250.github.io/piholemanual/doc/Block%20DOH%20wi... really digs into the nitty gritty of how to do it to a crazy extent.
Probably the only way to really block it is some kind of SSL unwrapping and deep packet inspection at the firewall but that's a HUGE hassle to deal with and is itself a potential privacy issue.
Personally, I think DoH was a mistake. Instead of the network admin configuring the name resolution services (via DHCP, for example) each app has a hard-coded list of IP addresses that it will use to resolve hostnames. Instead of a system resolver that does the job we now have a resolver, complete with hard-coded server configuration, baked into various applications/devices.
I run my own DNS, I would have said all the same things they did.
- Local caching reduces upstream queries significantly, making it much harder for upstream to profile you.
- Encrypt DNS traffic for incompatible devices.
In order to accomplish those things I rely on Response Policy Zones and Dnstap, features which I don't see listed for this server. Nonetheless it does have filtering capability and decent coverage of features important to the average internet user, based on their listed features.
[I give away the RPZ / Dnstap stuff on GitHub, and I use BIND.]
And about 150M of virtual memory on my rpi.
Edit: Argh, I thought you meant pihole, sorry for the confusion
VSZ RSS
275156560 151048
using lxc info Memory 276.90MiB Swap 16.00KiBwow, that is a PITA, just trying to be helpful. Anyway, seems a lot of virtual but next to no real memory.
edit: as I said, aside from the scary VM size, very small. I only have 60 local hosts though.
edit: ps, the dhcp/dns integration first class. I have a few networks and run a couple of dhcp namespaces and it all works perfectly, with multiple routes distributed. I could never get that going with piHole. I was running dndmasq for years before that.
>what does this do better than pi-hole does?
I block or redirect a few external DNS servers, like Google's, to a local DNS server and some devices go absolutely abeshit if the reply doesn't look like they expect. Like thousands of DNS lookups in minutes. Enough to kill pi-hole both on an RPI4, but also running on the same server as Technitium (dual Xeon proliant). So it seems it is more robust?
Also, even if you run AdGuard as DNS on local network, you still need to run it on your macOS, if you are planning to travel.
A suggestion for tho$e with multiple users: set up multiple PiHoles on your same network, then have "blocking levels" which each user can set up, e.g: 192.168.0.2 x.x.x.3 x.x.x.4 x.x.x.5 x.x.x.n
My DHCP auto-issues the "lowest level of blocking" PiHole to any client not specifying their own DNS (only 7 rules, mostly blocking pagead2 and doubleclick). Phones all point to a phone-specific local PiHole IP (which allows them to do phone-ier things). From there, users can block more ads simply by increasing the DNS IP by x.x.x.+1 [until shit stops working for them, then bump down 1].
For malingering DNS resolution issues, I'll sit down with the user/client and help them "massage the blocks" between x.x.x.n , but this is rare after the initial week or so of setup.
This also allows individual clients to entirely bypass your PiHoles, simply by them manually setting their DNS to x.x.x.1 [i.e. their router's IP].
----
YES I know that you can have a single PiHole resolve differently based on client IP, but my above solution allows for a much-simpler "levels of DNS protection" that most non-technical users can understand/modify, themselves. It is not inexpensive =D
I would say it’s a trade off, but with a positive value.
Insidious things, tsk tsk.
Also make sure to block outgoing TCP and UDP 853 – this blocks DoT and DoQ too.
Who is behind this software and what's their motivation for it?
PiHole is very simple in that regard, it was created by some dude to fill a niche and has grown into a reasonably robust community which should be reasonably resilient to outside attacks (someone sneaking in a change which adds a "feature" which exfiltrates and sells my data).
AdGuard also is a very known company with an obvious motive, to sell you their software, but they've been around a long time and are widely used and seem relatively harmless.
I'm sure I'm a cynic at this point, but, I feel like I need to know who these guys are and why they are willing to invest in this.