[HN Gopher] Gambling and Adult content DNS blocking using Mullva...
___________________________________________________________________
Gambling and Adult content DNS blocking using Mullvad VPN
Author : amirmasoudabdol
Score : 113 points
Date : 2022-07-13 09:22 UTC (13 hours ago)
(HTM) web link (mullvad.net)
(TXT) w3m dump (mullvad.net)
| kmfrk wrote:
| Does the Adult content filter trigger Restricted Mode on YouTube
| like CloudFlare's 1.1.1.3?
|
| That was the one reason I had to give up using adult filters like
| that.
| shimonamit wrote:
| I use SafeDNS which filters adult content (plus many more
| categories), without forcing YouTube Restricted Mode. But, you
| can opt into YouTube Restricted Mode if you choose.
| wzdd wrote:
| I do like the way they let you choose any combination of four
| blockers by setting individual bits in the last octet of the DNS
| server address.
| bragr wrote:
| Good catch! I didn't notice that on my first skim.
| crikeyjoe wrote:
| JadoJodo wrote:
| I wish there was the option to use both Mullvad + NextDNS.
| stblack wrote:
| I'm Steven Black and they cite my repo as their source for adult
| content domains.
|
| Mullvad VPN seems unclear on the concept, at least in regard to
| my resource.
|
| Using my porn hosts variant directly, they are presently pulling-
| in 188,735 domains, of which only 43,108 are porn domains. The
| other domains are adware, malware, etc.
|
| I also notice the mullvad/dns-adblock repository been in
| existence since June 7 2022, the date of its first commit. So
| this is a very new thing.
| Thorentis wrote:
| Why did you include adware and malware domains in a list named
| to suggest it only contains pornography domains then? Seems
| like a fair mistake on Mullvad's part.
| [deleted]
| square_usual wrote:
| Someone else posted that this isn't a feature they would look for
| in a VPN, and I'd _mostly_ agree except for one big problem: VPNs
| are the only way to effectively block things in iOS and (un-
| rooted) Android, and you can only have one VPN active at a time.
| This means that you have to choose between either having a proper
| VPN connected or a fake one to block content you don 't like.
| Mullvad's ads, trackers and malware blocking DNS has been
| _awesome_ when I 'm on my iPhone and don't want to deal with ads
| in apps. I'm sure some other people who have dependence issues
| with gambling or adult content would appreciate being able to use
| their preferred VPN while also blocking content.
| tambeb wrote:
| Android, since Pie, supports DNS over TLS, and I personally use
| it for ad blocking.
| sillysaurusx wrote:
| Wait, Mullvad acts as an adblocker for iOS? That's wonderful. I
| didn't know such a thing existed.
| [deleted]
| neonsunset wrote:
| If you only need Safari, AdGuard does a surprisingly good job,
| far superior than what you can get on Android.
| ugjka wrote:
| On Android you can have Firefox with uBlock origin
| hgazx wrote:
| He said superior.
| scopecreep wrote:
| Doesn't AdGuard allow 'approved ads'?
| Arubis wrote:
| Without disagreeing that folks would want an all-in-one
| solution, a potential alternative is to use a service like
| https://nextdns.io/ in addition to your VPN.
| comprev wrote:
| Upvote for NextDNS. Their platform has been a game changer
| for me on all devices/computers and really enjoy the
| granularity of filtering. Happy customer here!
| notRobot wrote:
| On Android, the NextDNS app registers itself as a VPN, so you
| can't use it simultaneously with, say, Mullvad.
|
| The custom DNS option in Android's network settings rarely
| seems to work in my experience, but I haven't tried in a
| couple years.
| onlyusername wrote:
| >On Android, the NextDNS app registers itself as a VPN
|
| It does this for macOS and iOS too, which has caused issues
| when both were trying to set the DNS on the machines.
| whatsthatabout wrote:
| This is particularly unlucky for macOS if you want to use
| a application-firewall like "Little Snitch" - since Apple
| removed kernelextensions on macOS (which LittleSnitch and
| others used before) they now have to also fake a VPN.
| Because of this, you cannot use a custom DNS and Little
| Snitch. [1]
|
| [1]:https://github.com/AdguardTeam/AdGuardDNS/issues/214
| sha-3 wrote:
| It has almost always worked on my devices though.
| zinekeller wrote:
| If you're only using Pixels, don't underestimate how bad
| OEMs can screw up their version of Android.
| yewenjie wrote:
| Doesn't Android have a private DNS server option now?
| rand49an wrote:
| Yes, I NextDNS with this option and it works great.
| achairapart wrote:
| On iOS you can install a configuration profile that setup a
| DNS-over-HTTPS endpoint without touching the VPN settings.
| NextDNS does this when you install their app from what I
| remember. For other examples, see the profiles offered by
| AhaDNS.com[0].
|
| On Android there is a Private DNS option where you can also
| setup a DNS-over-HTTPS endpoint of your choice.
|
| These options may be also a better choice for battery life than
| a fake VPN connection.
|
| [0]: https://github.com/AhaDNS/setup-
| guides/blob/master/Apple/iOS...
| Scoundreller wrote:
| Just did this last week, and it's been life changing over
| mobile:
|
| https://news.ycombinator.com/item?id=32041238#32041742
| whatsthatabout wrote:
| Is this really true? Because on macOS exactly this
| "workaround" does not work:
| https://github.com/AdguardTeam/AdGuardDNS/issues/214
| TheGoddessInari wrote:
| The very thing you're linking to is because of running
| conflicting software on MacOS.
| whatsthatabout wrote:
| Yes I know but that's what the parent comment(s) are
| about? Using a profile for DNS settings instead of a fake
| VPN because you can't run more than one active VPN at a
| time.
| achairapart wrote:
| Sorry, I can't tell for macOS, but on iOS i have a few DNS
| profiles and they all seems to work.
| whatsthatabout wrote:
| In addition to running a VPN? That's what the main
| comment was about, wasn't it? The profiles alone do work.
| achairapart wrote:
| As I understood it was about blocking content (via DNS)
| *even without a fake VPN connection*. Once you run a VPN
| connection, most likely its DNS takes over, profile or
| not profile.
| rsync wrote:
| The android setting wherein you can input a standard DNS-
| over-HTTPS endpoint is sensible and sane.
|
| Is it, in fact, correct that there is no such setting in iOS
| and has to be app-enabled ? Or are you saying I can _either_
| manage the device with configurator2 and put that setting in
| _or_ I can install an app (like nextdns) that does it for me
| ?
|
| Really frustrating that simple config options like _DNS
| server_ and setting the name of your hotspot SSID are
| nonexistent in iOS ...
| achairapart wrote:
| In iOS from what I know you need a configuration profile
| for that, I don't think it needs to be signed.
|
| Yes, you can make one with Apple Configurator 2, but there
| is also some tooling/app that may help, like:
|
| https://dns.notjakob.com/
|
| https://github.com/kkk669/DNSecure
| cntrl wrote:
| By using a WireGuard VPN you could actually be connected to
| multiple endpoints at a time, if you are able to set the same
| tunnel IP for all endpoints. That would enable you to have that
| one connection open routing to different servers (Mullvad /
| Homelab / Offsite Lab / Work / etc ...) hence also using your
| own DNS resolver with a commercial VPN.
| jeroenhd wrote:
| As I've recently been made aware here on HN, on Android system
| applications can bind to an arbitrary interface so they can
| effectively bypass the VPN system. I don't think it happens
| often in practice, but it's something to keep in mind.
| flas9sd wrote:
| on paper (Android 8 and up) has the always-on type VPN that
| blocks any network connection not using the vpn (disallows
| bypass). Didn't poke it yet how it works if multiple apps
| create VPNs, I assume only one VPN of this type can be active
| freetime2 wrote:
| Can you build one that blocks all non-adult and non-gambling
| content? Asking for a friend...
| jacquesm wrote:
| He could but then you wouldn't be able to read his answer...
| lostlogin wrote:
| I'll take that bet.
| tr1ll10nb1ll wrote:
| "Vices DNS", that's what I'd call it.
| [deleted]
| [deleted]
| ibejoeb wrote:
| Sorry for the tangent, but does anyone have a solution for
| mdns/ssdp (Sonos, in my case) while running Mullvad with
| wireguard?
|
| edit: nvm, was trivial to just route it manually. For anyone
| interested, just something like ip route add
| 239.255.255.250 dev <whichever interface>
|
| There probably something more elegant in a wg config somewhere,
| but this does the job.
| pluc wrote:
| PiHole lists to achieve the same thing:
|
| https://oisd.nl/downloads
|
| https://github.com/blocklistproject/Lists/
| bishopsmother wrote:
| Unfortunately some apps[0] are already resistant to DNS-based
| blocking, which is why I'm creating SocialsDetox (DoH & VPN).
| It allows blocking of social media (+others, e.g. Gambling)
| across all your devices with a single click, scheduled and/or
| API call.
|
| [0] https://www.tigerdroppings.com/rant/tech/facebook-app-and-
| un...
| [deleted]
| gojou wrote:
| The issue there is pihole is only useful on your local network.
| You could expose it to the internet but that's a horrible idea.
| You could also VPN into your home network I guess but that's
| often not feasible.
| mrchucklepants wrote:
| I do exactly this. I have WireGuard running on my pihole
| server. All my devices are set to connect automatically when
| off my home network.
| martin_a wrote:
| > You could expose it to the internet but that's a horrible
| idea.
|
| Been there, done that. It was a mistake. Not sure which
| attacks my public PiHole was part of, but I surely was part
| of some.
|
| It's a shame, I'd really like to offer this as a service to
| friends, because I think they would be able to change the DNS
| settings of their routers and enjoy a safer surfing
| experience.
|
| I don't want to get started with distributing key pairs to
| connect to a VPN and whatnot. PiHole really has a sweet spot
| there with its ease-of-use but it fails in regards of
| security/protection against becoming part of DNS-based
| attacks.
| bush-bby wrote:
| > Been there, done that. It was a mistake. Not sure which
| attacks my public PiHole was part of, but I surely was part
| of some.
|
| How did you come to this conclusion? How did you come to
| know?
| martin_a wrote:
| The PiHole has some integrated logging where you can see
| the requests that were made. I had several IPs which were
| doing queries for the same domains dozens of times per
| second. That wasn't a poweruser but some kind of
| automated system, probably doing reflection attacks or
| sth. alike.
|
| I think PiHole has improved since that time, you can now
| set throttling, but I'm not sure I'd run a public PiHole
| anymore.
| pluc wrote:
| pihole + fail2ban
|
| google that my man
| martin_a wrote:
| Thanks! Only knew fail2ban from securing SSH, but yeah,
| works for other daemons, too...
| unethical_ban wrote:
| I run Pi-hole and pi-vpn on a VM at home, and have my mobile
| phone set to always-on VPN. I have occasionally had to
| disable the VPN on public wifi that blocks the high UDP port,
| but I think that could be gotten around with udp/443 which is
| used by QUIC/Google a lot. udp/53 inbound is blocked on my
| ATT home network.
| lostlogin wrote:
| > You could also VPN into your home network I guess.
|
| It works beautifully. I think it hurts battery life on
| phones, but that hasn't been tested by me in any meaningful
| way.
| pluc wrote:
| There are PiHole-as-a-Service... services out there
| xnyan wrote:
| As others say, use a VPN like wireguard. If bandwidth or
| latency over the VPN is a concern, you can setup your VPN to
| only route DNS requests over the VPN.
| rrix2 wrote:
| My pihole listens only on my server's TailScale interface,
| and have MagicDNS set to use the server's tailnet IP. Phone
| and laptops get it using the app, LAN gets it with subnet
| routing.
___________________________________________________________________
(page generated 2022-07-13 23:02 UTC)