Most people already use a centralized resolver like Google or Cloudflare anyway, and you can be sure those will be patched. People who use their ISP’s resolver might be disappointed if their ISP is slow to patch things, but what else is new?
Most people already use a centralized resolver like Google or Cloudflare anyway, and you can be sure those will be patched. People who use their ISP’s resolver might be disappointed if their ISP is slow to patch things, but what else is new?
Bear in mind that if you're using a regular port 53 resolver like Google's, you might be using your ISP's resolver anyway -- a lot of ISP's hijack port 53 and redirect it to their own server(s) to reduce load. That's why DNS over TLS / HTTPS is typically recommended over unencrypted DNS.
To disable it you have to call them and ask.
Nope, validating in stubs is a thing. systemd's resolved does it. Apple's high-level network frameworks do it if you ask as of a couple of years ago (they've been back and forth on DNSSEC in their lower level API for longer than that). I'm not sure how well they work but they're there.
Every iPhone on the planet might as well be a recursive resolver? Yeah, nah.
Stub resolver: A resolver that cannot perform all resolution itself.
Stub resolvers generally depend on a recursive resolver to
undertake the actual resolution function.That's right, it's not recursively working its way down from the root because it's a stub resolver.
(Nearly) all the wifi/routers supplied with NBN are locked to the ISP's DNS.
You can arrange to get your own wifi/router and of course you can set your own individual machine to ignore DHCP settings. But that would be rare.
That said friends don't let friends do anything else than install pi-hole as the dhcp server using unbound for dns. It's never too late but do it today. I'm 100% sure this is possible in Australia.
I can and do put it in bridge mode and use my own router, but I was quite surprised and miffed to see this. First time I've ever come across that.
The router is a Comcast / Xfinity XB6 and I've been told that this is a "feature" of all of Comcast's routers / gateways.
so you connect $something to the cable modem. Make a dhcp request and get back your public ip (and some dns servers). But it isn't doing nat or handing out local addresses to your local network. Right?
_Or_
it's a combined modem-and-router-in-one which manages your local subnet for you and you can't configure how it does this at all beyond switching the router part off and using a separate router. That sounds nuts?
Free lets you configure custom DNS servers to be sent in the DHCP reply.
Get your own router if you want to change it. And that has various downsides.
I love my pi hole and have been encouraging friends lol
This is HN. I run unbound on a Pi (mentioning the Pi I don't know if those running PiHole are running a vulnerable resolver or not). My Pi shall need patching when I get back from vacation!
https://support.mozilla.org/en-US/kb/firefox-dns-over-https#...
Chrome followed:
https://duo.com/decipher/google-makes-dns-over-https-default...