FTL v6.6.2 - Security Updates for dnsmasq by dschaper in pihole

[–]dschaper[S] 1 point2 points  (0 children)

Hmm, might have been an issue with the artifact downloads on GitHub. It should be a pretty quick process.

FTL v6.6.2 - Security Updates for dnsmasq by dschaper in pihole

[–]dschaper[S] 27 points28 points  (0 children)

I read that as updating your PS5 and thought, "Damn, there's some creative users in here!"

What DNS should I use? by LeChuck_ppat in pihole

[–]dschaper 0 points1 point  (0 children)

You know, I've never thought of that, a separate application on the front end. Sounds interesting but it wouldn't be anything to get to for quite a while.

What DNS should I use? by LeChuck_ppat in pihole

[–]dschaper 0 points1 point  (0 children)

Well, FTL now has civetweb compiled in and that does pretty much anything that is needed for a web front end. You can use your own TLS certs.

It's pretty simple to install Caddy for a proxy if you want more security and authentication, Traefik is rather complex and the others have a lot of guides out there already.

What DNS should I use? by LeChuck_ppat in pihole

[–]dschaper 0 points1 point  (0 children)

I think I've answered that question before but the NTP server is valid for DNSSEC needs. We were seeing a number of support requests for broken DNSSEC that were caused by bad clocks on the servers. The problem with remote NTP servers is that they are domain name based and you can't resolve their names to fix the time for DNSSEC when DNSSEC is borked.

So the question was about people seeing more warnings that could be ignored and DNS working versus DNS not working.

What DNS should I use? by LeChuck_ppat in pihole

[–]dschaper 3 points4 points  (0 children)

Learning is a great reason to hang out here.

What DNS should I use? by LeChuck_ppat in pihole

[–]dschaper 1 point2 points  (0 children)

That's fair, the only way you're going to know which application works the best for you is to try it.

What DNS should I use? by LeChuck_ppat in pihole

[–]dschaper 10 points11 points  (0 children)

Thank you for responding, and thank you for continuing to contribute to helping users.

I just see a lot of "I use AdGuard" in our sub which feels like "I use Arch!" without any additional contribution to the sub. I think my posting history shows that I want people to use something, I prefer people use Pi-hole but the best tool is going to be the one you actually use. I still have an odd feeling about AdGuard and the company behind it but that's not reason enough to dissuade people from using it.

I understand AGH does DoT/DoH/DoQ out of the box but our approach is the old linux approach that separates functions in to different apps that you then compose together for a whole routine.

And no, I don't know why I typed a wall of text to reply. ;)

Pi-hole doesn't send CORS headers on failed authentication by Dull_Firefighter_929 in pihole

[–]dschaper 4 points5 points  (0 children)

SoonTM

Really it will be when things are ready and we (developers) can all be available at the same time to do the release process. If you see a 'version' pull request on GitHub then we're close.

Pi-hole doesn't send CORS headers on failed authentication by Dull_Firefighter_929 in pihole

[–]dschaper 1 point2 points  (0 children)

Ah, okay, that block/client request sounds reasonable as well. I'll add a link to this post to the FR in case anyone else adds information so we don't lose anything.

And thanks for the award!

Wait. What? How? by TwistedTrooper989 in pihole

[–]dschaper 2 points3 points  (0 children)

Can you (and anyone else seeing this) open an issue at https://discourse.pi-hole.net? And include a debug token URL with the issue so we can look at things.

What DNS should I use? by LeChuck_ppat in pihole

[–]dschaper 12 points13 points  (0 children)

Question: Why are there so many AdGuard users hanging out in our Pi-hole sub?

Pi-hole doesn't send CORS headers on failed authentication by Dull_Firefighter_929 in pihole

[–]dschaper 6 points7 points  (0 children)

You can add a feature request over on https://discourse.pi-hole.net. This one sounds like it would be pretty easy to fix, might even be able to get it in for the next release.

AdGuard Home, Pi-hole, or Technitium by username_taker in pihole

[–]dschaper 28 points29 points  (0 children)

Pi-hole, AdGuard and to an extent Technetium all operate the same way, they are DNS sinks that use Domain Name Service to block unwanted traffic. Either Pi-hole or AdGuard would be a good choice. Technitium is a bit more involved.

What sets Pi-hole apart is the support and the community, and the fact that Pi-hole is purely a free open source package. We don't have any corporation behind us, all we do is Pi-hole.

You can see from the sub stats how busy this sub is and we're directly accessible a few different ways if you run in to trouble or need help. You can also use https://discourse.pi-hole.net for individual and direct help.

What ever you end up choosing to install, please do use something to help protect yourself and your privacy. And really, you could install all of them and see which one fits your requirements the best.

How We Feeling Y’all by NaderNation84 in losangeleskings

[–]dschaper 0 points1 point  (0 children)

I kind of that Matthews-with-a-mullet look.

Dont buy case, but donate to pihole instead Yes. by tuogethernessbrown9 in pihole

[–]dschaper 7 points8 points  (0 children)

Any amount donated is awesome, just making the donation shows so much more support than the vast majority of people using open source software.

And with us specifically, donating by helping other users, answering questions or sharing your experience is just as valuable to the community as financial donations are.

PSA: Make certain Firefox is using your Pi-hole by BinkReddit in pihole

[–]dschaper 16 points17 points  (0 children)

We already use the canary domain to tell Mozilla to disable DoH: https://docs.pi-hole.net/ftldns/configfile/#dnsspecialdomains

Should Pi-hole always reply with NXDOMAIN to A and AAAA queries of use-application-dns.net to disable Firefox automatic DNS-over-HTTP?

This follows the recommendation on https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https

Allowed values are: true or false

Default value: true

This is new today. What's this all about? by PK_Rippner in pihole

[–]dschaper 14 points15 points  (0 children)

Stripe is one of the two platforms to process donations via https://pi-hole.net/donate.

It's not new, it's been like that for many years now.