[HN Gopher] Gambling and Adult content DNS blocking using Mullva...
       ___________________________________________________________________
        
       Gambling and Adult content DNS blocking using Mullvad VPN
        
       Author : amirmasoudabdol
       Score  : 113 points
       Date   : 2022-07-13 09:22 UTC (13 hours ago)
        
 (HTM) web link (mullvad.net)
 (TXT) w3m dump (mullvad.net)
        
       | kmfrk wrote:
       | Does the Adult content filter trigger Restricted Mode on YouTube
       | like CloudFlare's 1.1.1.3?
       | 
       | That was the one reason I had to give up using adult filters like
       | that.
        
         | shimonamit wrote:
         | I use SafeDNS which filters adult content (plus many more
         | categories), without forcing YouTube Restricted Mode. But, you
         | can opt into YouTube Restricted Mode if you choose.
        
       | wzdd wrote:
       | I do like the way they let you choose any combination of four
       | blockers by setting individual bits in the last octet of the DNS
       | server address.
        
         | bragr wrote:
         | Good catch! I didn't notice that on my first skim.
        
       | crikeyjoe wrote:
        
       | JadoJodo wrote:
       | I wish there was the option to use both Mullvad + NextDNS.
        
       | stblack wrote:
       | I'm Steven Black and they cite my repo as their source for adult
       | content domains.
       | 
       | Mullvad VPN seems unclear on the concept, at least in regard to
       | my resource.
       | 
       | Using my porn hosts variant directly, they are presently pulling-
       | in 188,735 domains, of which only 43,108 are porn domains. The
       | other domains are adware, malware, etc.
       | 
       | I also notice the mullvad/dns-adblock repository been in
       | existence since June 7 2022, the date of its first commit. So
       | this is a very new thing.
        
         | Thorentis wrote:
         | Why did you include adware and malware domains in a list named
         | to suggest it only contains pornography domains then? Seems
         | like a fair mistake on Mullvad's part.
        
       | [deleted]
        
       | square_usual wrote:
       | Someone else posted that this isn't a feature they would look for
       | in a VPN, and I'd _mostly_ agree except for one big problem: VPNs
       | are the only way to effectively block things in iOS and (un-
       | rooted) Android, and you can only have one VPN active at a time.
       | This means that you have to choose between either having a proper
       | VPN connected or a fake one to block content you don 't like.
       | Mullvad's ads, trackers and malware blocking DNS has been
       | _awesome_ when I 'm on my iPhone and don't want to deal with ads
       | in apps. I'm sure some other people who have dependence issues
       | with gambling or adult content would appreciate being able to use
       | their preferred VPN while also blocking content.
        
         | tambeb wrote:
         | Android, since Pie, supports DNS over TLS, and I personally use
         | it for ad blocking.
        
         | sillysaurusx wrote:
         | Wait, Mullvad acts as an adblocker for iOS? That's wonderful. I
         | didn't know such a thing existed.
        
           | [deleted]
        
         | neonsunset wrote:
         | If you only need Safari, AdGuard does a surprisingly good job,
         | far superior than what you can get on Android.
        
           | ugjka wrote:
           | On Android you can have Firefox with uBlock origin
        
             | hgazx wrote:
             | He said superior.
        
               | scopecreep wrote:
               | Doesn't AdGuard allow 'approved ads'?
        
         | Arubis wrote:
         | Without disagreeing that folks would want an all-in-one
         | solution, a potential alternative is to use a service like
         | https://nextdns.io/ in addition to your VPN.
        
           | comprev wrote:
           | Upvote for NextDNS. Their platform has been a game changer
           | for me on all devices/computers and really enjoy the
           | granularity of filtering. Happy customer here!
        
           | notRobot wrote:
           | On Android, the NextDNS app registers itself as a VPN, so you
           | can't use it simultaneously with, say, Mullvad.
           | 
           | The custom DNS option in Android's network settings rarely
           | seems to work in my experience, but I haven't tried in a
           | couple years.
        
             | onlyusername wrote:
             | >On Android, the NextDNS app registers itself as a VPN
             | 
             | It does this for macOS and iOS too, which has caused issues
             | when both were trying to set the DNS on the machines.
        
               | whatsthatabout wrote:
               | This is particularly unlucky for macOS if you want to use
               | a application-firewall like "Little Snitch" - since Apple
               | removed kernelextensions on macOS (which LittleSnitch and
               | others used before) they now have to also fake a VPN.
               | Because of this, you cannot use a custom DNS and Little
               | Snitch. [1]
               | 
               | [1]:https://github.com/AdguardTeam/AdGuardDNS/issues/214
        
             | sha-3 wrote:
             | It has almost always worked on my devices though.
        
               | zinekeller wrote:
               | If you're only using Pixels, don't underestimate how bad
               | OEMs can screw up their version of Android.
        
         | yewenjie wrote:
         | Doesn't Android have a private DNS server option now?
        
           | rand49an wrote:
           | Yes, I NextDNS with this option and it works great.
        
         | achairapart wrote:
         | On iOS you can install a configuration profile that setup a
         | DNS-over-HTTPS endpoint without touching the VPN settings.
         | NextDNS does this when you install their app from what I
         | remember. For other examples, see the profiles offered by
         | AhaDNS.com[0].
         | 
         | On Android there is a Private DNS option where you can also
         | setup a DNS-over-HTTPS endpoint of your choice.
         | 
         | These options may be also a better choice for battery life than
         | a fake VPN connection.
         | 
         | [0]: https://github.com/AhaDNS/setup-
         | guides/blob/master/Apple/iOS...
        
           | Scoundreller wrote:
           | Just did this last week, and it's been life changing over
           | mobile:
           | 
           | https://news.ycombinator.com/item?id=32041238#32041742
        
           | whatsthatabout wrote:
           | Is this really true? Because on macOS exactly this
           | "workaround" does not work:
           | https://github.com/AdguardTeam/AdGuardDNS/issues/214
        
             | TheGoddessInari wrote:
             | The very thing you're linking to is because of running
             | conflicting software on MacOS.
        
               | whatsthatabout wrote:
               | Yes I know but that's what the parent comment(s) are
               | about? Using a profile for DNS settings instead of a fake
               | VPN because you can't run more than one active VPN at a
               | time.
        
             | achairapart wrote:
             | Sorry, I can't tell for macOS, but on iOS i have a few DNS
             | profiles and they all seems to work.
        
               | whatsthatabout wrote:
               | In addition to running a VPN? That's what the main
               | comment was about, wasn't it? The profiles alone do work.
        
               | achairapart wrote:
               | As I understood it was about blocking content (via DNS)
               | *even without a fake VPN connection*. Once you run a VPN
               | connection, most likely its DNS takes over, profile or
               | not profile.
        
           | rsync wrote:
           | The android setting wherein you can input a standard DNS-
           | over-HTTPS endpoint is sensible and sane.
           | 
           | Is it, in fact, correct that there is no such setting in iOS
           | and has to be app-enabled ? Or are you saying I can _either_
           | manage the device with configurator2 and put that setting in
           | _or_ I can install an app (like nextdns) that does it for me
           | ?
           | 
           | Really frustrating that simple config options like _DNS
           | server_ and setting the name of your hotspot SSID are
           | nonexistent in iOS ...
        
             | achairapart wrote:
             | In iOS from what I know you need a configuration profile
             | for that, I don't think it needs to be signed.
             | 
             | Yes, you can make one with Apple Configurator 2, but there
             | is also some tooling/app that may help, like:
             | 
             | https://dns.notjakob.com/
             | 
             | https://github.com/kkk669/DNSecure
        
         | cntrl wrote:
         | By using a WireGuard VPN you could actually be connected to
         | multiple endpoints at a time, if you are able to set the same
         | tunnel IP for all endpoints. That would enable you to have that
         | one connection open routing to different servers (Mullvad /
         | Homelab / Offsite Lab / Work / etc ...) hence also using your
         | own DNS resolver with a commercial VPN.
        
         | jeroenhd wrote:
         | As I've recently been made aware here on HN, on Android system
         | applications can bind to an arbitrary interface so they can
         | effectively bypass the VPN system. I don't think it happens
         | often in practice, but it's something to keep in mind.
        
           | flas9sd wrote:
           | on paper (Android 8 and up) has the always-on type VPN that
           | blocks any network connection not using the vpn (disallows
           | bypass). Didn't poke it yet how it works if multiple apps
           | create VPNs, I assume only one VPN of this type can be active
        
       | freetime2 wrote:
       | Can you build one that blocks all non-adult and non-gambling
       | content? Asking for a friend...
        
         | jacquesm wrote:
         | He could but then you wouldn't be able to read his answer...
        
           | lostlogin wrote:
           | I'll take that bet.
        
         | tr1ll10nb1ll wrote:
         | "Vices DNS", that's what I'd call it.
        
         | [deleted]
        
       | [deleted]
        
       | ibejoeb wrote:
       | Sorry for the tangent, but does anyone have a solution for
       | mdns/ssdp (Sonos, in my case) while running Mullvad with
       | wireguard?
       | 
       | edit: nvm, was trivial to just route it manually. For anyone
       | interested, just something like                 ip route add
       | 239.255.255.250 dev <whichever interface>
       | 
       | There probably something more elegant in a wg config somewhere,
       | but this does the job.
        
       | pluc wrote:
       | PiHole lists to achieve the same thing:
       | 
       | https://oisd.nl/downloads
       | 
       | https://github.com/blocklistproject/Lists/
        
         | bishopsmother wrote:
         | Unfortunately some apps[0] are already resistant to DNS-based
         | blocking, which is why I'm creating SocialsDetox (DoH & VPN).
         | It allows blocking of social media (+others, e.g. Gambling)
         | across all your devices with a single click, scheduled and/or
         | API call.
         | 
         | [0] https://www.tigerdroppings.com/rant/tech/facebook-app-and-
         | un...
        
         | [deleted]
        
         | gojou wrote:
         | The issue there is pihole is only useful on your local network.
         | You could expose it to the internet but that's a horrible idea.
         | You could also VPN into your home network I guess but that's
         | often not feasible.
        
           | mrchucklepants wrote:
           | I do exactly this. I have WireGuard running on my pihole
           | server. All my devices are set to connect automatically when
           | off my home network.
        
           | martin_a wrote:
           | > You could expose it to the internet but that's a horrible
           | idea.
           | 
           | Been there, done that. It was a mistake. Not sure which
           | attacks my public PiHole was part of, but I surely was part
           | of some.
           | 
           | It's a shame, I'd really like to offer this as a service to
           | friends, because I think they would be able to change the DNS
           | settings of their routers and enjoy a safer surfing
           | experience.
           | 
           | I don't want to get started with distributing key pairs to
           | connect to a VPN and whatnot. PiHole really has a sweet spot
           | there with its ease-of-use but it fails in regards of
           | security/protection against becoming part of DNS-based
           | attacks.
        
             | bush-bby wrote:
             | > Been there, done that. It was a mistake. Not sure which
             | attacks my public PiHole was part of, but I surely was part
             | of some.
             | 
             | How did you come to this conclusion? How did you come to
             | know?
        
               | martin_a wrote:
               | The PiHole has some integrated logging where you can see
               | the requests that were made. I had several IPs which were
               | doing queries for the same domains dozens of times per
               | second. That wasn't a poweruser but some kind of
               | automated system, probably doing reflection attacks or
               | sth. alike.
               | 
               | I think PiHole has improved since that time, you can now
               | set throttling, but I'm not sure I'd run a public PiHole
               | anymore.
        
               | pluc wrote:
               | pihole + fail2ban
               | 
               | google that my man
        
               | martin_a wrote:
               | Thanks! Only knew fail2ban from securing SSH, but yeah,
               | works for other daemons, too...
        
           | unethical_ban wrote:
           | I run Pi-hole and pi-vpn on a VM at home, and have my mobile
           | phone set to always-on VPN. I have occasionally had to
           | disable the VPN on public wifi that blocks the high UDP port,
           | but I think that could be gotten around with udp/443 which is
           | used by QUIC/Google a lot. udp/53 inbound is blocked on my
           | ATT home network.
        
           | lostlogin wrote:
           | > You could also VPN into your home network I guess.
           | 
           | It works beautifully. I think it hurts battery life on
           | phones, but that hasn't been tested by me in any meaningful
           | way.
        
           | pluc wrote:
           | There are PiHole-as-a-Service... services out there
        
           | xnyan wrote:
           | As others say, use a VPN like wireguard. If bandwidth or
           | latency over the VPN is a concern, you can setup your VPN to
           | only route DNS requests over the VPN.
        
           | rrix2 wrote:
           | My pihole listens only on my server's TailScale interface,
           | and have MagicDNS set to use the server's tailnet IP. Phone
           | and laptops get it using the app, LAN gets it with subnet
           | routing.
        
       ___________________________________________________________________
       (page generated 2022-07-13 23:02 UTC)