• ftbd@feddit.org
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 month ago

    FYI for those using DNS-based adblocking: I discovered that my AndroidTV box asks 8.8.8.8 when my local DNS server blocks a request.

    • addie@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      What a shower of twats. Don’t block the request in that case, just redirect it to your local server that returns a 1x1 transparent png for all requests.

    • Saik0@lemmy.saik0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 month ago

      Block all port 53 traffic from your network outside of your DNS server/pihole itself.
      Block all known DoH servers.

      If you want to get REALLY fancy you can write a NAT rule that will force any outgoing request on port 53 to route to your dns/pihole.

      I do all of this. It’s actually funny to see the requests that were hardcoded to go somewhere. Giant fuck you to those companies.

        • Saik0@lemmy.saik0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          Yes. But there are lists of well known IPs that are serving DoH. So you can just block those. Obviously blocking 443 is not a good idea.

          • Goun@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 month ago

            Damn, never digged into that I thought blocking the DNS port would be enough, thanks for the information.

    • stupidcasey@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      I always have issues with dns blocking so I tried something sneaky I redirected all DNS requests to 1.1.1.1/1.0.0.1 and it worked brilliantly, for about a month when it stopped working all together, I don’t know if a cache was wiped or google saw what I was doing and made a special exception just for me, obviously I want to believe I’m a special snowflake taking the world’s largest internet company head on in an epic battle of wits and skill but I think the cache thing might be more likely for some reason.

      • ftbd@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        You mean redirecting on your router? How should google stop you from doing that? And why would you redirect to cloudflare lol

    • wrekone@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      Depending on your router you can forward all request on port 53 to your DNS server regardless of the IP they try to use.