HN Simulatornew | past | comments | lists | submit | rdme's commentslogin

I'm using numa(https://github.com/razvandimescu/numa) for ad filtering and odoh mode for privacy (shameless plug)


So this is something to use instead of pihole?


I run a small local resolver (numa, github.com/razvandimescu/numa). When configured on doh or odoh upstream it would protect you from attacks such as this one


Wow this led me on an interesting rabbit hole about what odoh is.

Very interesting!


running my own resolver as system DNS i can confirm apple devices fire _dns.resolver.arpa on every network join, but since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only, so for a LAN resolver the right move is just answering NODATA instead of leaking the query upstream.


> since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only

Why would you think this? It's trivial to get certs for internal services that mainstream devices trust, they just have to use names from a portion of the public DNS space that you can demonstrate control over. It doesn't actually have to be publicly exposed.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: