TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Setting Up 1.1.1.1 for Families on a Pi-Hole

80 pointsby bradley_tauntover 3 years ago

14 comments

freediverover 3 years ago
I did test 1.1.1.1 and found it to be pretty slow on long tail domains (obviously everyone is caching popular ones).<p>I bascially ran a &#x27;dig&#x27; with multiple DNS providers and CloudFlare was slowest among the bunch for long-tail domains.<p>Here are the details: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;vladquant&#x2F;status&#x2F;1428761979808669704" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;vladquant&#x2F;status&#x2F;1428761979808669704</a><p>CloudFlare never responded to this tweet.
评论 #29037246 未加载
评论 #29037359 未加载
评论 #29036246 未加载
评论 #29036241 未加载
whalesaladover 3 years ago
I’d urge everyone to run a dns bench tool at home. Cloudflare isn’t always the right choice and for some ISPs with routing issues it can sometimes be a bad choice.
评论 #29042422 未加载
评论 #29035769 未加载
评论 #29036846 未加载
评论 #29035671 未加载
评论 #29035597 未加载
pkulakover 3 years ago
I recently switched to AdGuard (hosted in Home Assistant), and I like it a bit better than PiHole. It seems more configurable.
closeneoughover 3 years ago
Yes, send more data to big companies like cloud front and google. They need it.
评论 #29036969 未加载
newscrackerover 3 years ago
The one thing Cloudflare DNS is missing is providing something like NextDNS.<p>Choose your own filter lists (that are constantly updated), create multiple profiles to use according to the target device&#x2F;location and enjoy as blocking at the DNS level. It’s not a complete match for something like uBlock Origin, but a lot of stuff still gets blocked with DNS filters.
评论 #29036869 未加载
deeblering4over 3 years ago
Congratulations, you&#x27;ve just sent all of your legitimate DNS traffic to a tracker (the thing pi-hole is usually deployed to avoid).<p>Remember that when a service is free, you are usually paying with your data.
评论 #29042700 未加载
JimWestergrenover 3 years ago
Anybody know from where does CF get the domains to block on 1.1.1.2 (malware) and 1.1.1.3 (porn)?
2Gkashmiriover 3 years ago
why? arent we already using pi-hole for blocking all the stuff?<p>that said, i have a query about a simple way to force all dns in a local network to pass through pi-hole. i only have access to the iSP router and pi-hole and cannot use third party router
评论 #29036424 未加载
评论 #29035643 未加载
评论 #29035707 未加载
评论 #29036352 未加载
iso1210over 3 years ago
I wonder how much ICMP is going to those IPs. I ping 1.0.0.1 (&quot;ping 1.1&quot;) as a quick check to ensure my internet is working a lot, far quicker and less stretching than typing ping 8.8.8.8. When I&#x27;m tracing a fault I&#x27;ll ping 1.1.1.x as I can then tcpdump on a spanport against that IP and be fairly confident any traffic is from my test point and not from another device.<p>I&#x27;m sure I&#x27;m not the only one.
评论 #29037540 未加载
评论 #29037506 未加载
t0bia_sover 3 years ago
1.1.1.3 for blocking also adult content, could be even faster than commonly used 1.1.1.1
truth_seekerover 3 years ago
I use Adguard DNS.<p><a href="https:&#x2F;&#x2F;adguard.com&#x2F;en&#x2F;adguard-dns&#x2F;overview.html" rel="nofollow">https:&#x2F;&#x2F;adguard.com&#x2F;en&#x2F;adguard-dns&#x2F;overview.html</a><p>DNS Servers:<p>94.140.14.15 94.140.15.16<p>Also, for android phones (via private DNS):<p>dns-family.adguard.com
danShumwayover 3 years ago
I still think this is a business that Cloudflare shouldn&#x27;t be involved in. There are very legitimate reasons for parents to filter Internet content. But Cloudflare is in a unique position here, they have a brand as a company that cares about free speech, and specifically because of who they are, they really shouldn&#x27;t be making determinations about what is and isn&#x27;t inappropriate content for kids.<p>When 1.1.1.1 for Families launched, it blocked access to GLADD&#x27;s site because Cloudflare didn&#x27;t do a good enough job testing any of this stuff and they just pulled in filters from other parental companies, some of which turned out to be anti-gay. Cloudflare apologized, pushed a couple of fixes, but never actually took a step back and asked how this happened. In the meantime, 1.1.1.1 for Families launched without blocking access to sites like Stormfront. Cloudlfare didn&#x27;t think it was appropriate for them to make a determination over whether that site was safe for kids.<p>I think that our society is just generally a lot less thoughtful about filtering adult content than it is about filtering other forms of content like political speech, and we don&#x27;t think about adult content filters as having a downside, or being real censorship. So when 1.1.1.1 for Families was released, I came up with a challenge: <a href="https:&#x2F;&#x2F;danshumway.com&#x2F;blog&#x2F;sex-censorship-is-censorship&#x2F;" rel="nofollow">https:&#x2F;&#x2F;danshumway.com&#x2F;blog&#x2F;sex-censorship-is-censorship&#x2F;</a><p>I do think there are scenarios where it&#x27;s completely appropriate to block content for children, and I do think families should always able to make these kinds of determinations. People and communities have a fundamental Right to Filter (<a href="https:&#x2F;&#x2F;anewdigitalmanifesto.com&#x2F;#right-to-filter" rel="nofollow">https:&#x2F;&#x2F;anewdigitalmanifesto.com&#x2F;#right-to-filter</a>). However, adult content isn&#x27;t the only content that falls into the category of being harmful to children. It is utter hypocrisy for Cloudflare to launch a service that blocks adult content but not hate speech; both forms of content are legitimate for parents to want off of their networks.<p>My challenge is, if Cloudflare is frightened of the implications of being the company that decides what is and isn&#x27;t hate speech, then why isn&#x27;t it <i>also</i> frightened of being the company that decides what is and isn&#x27;t adult material? Why do we view accidental censorship of LGBTQ+ informational materials as less of an existential free speech risk than accidental censorship of political ideas or extremist groups? Cloudflare still, over a year later, doesn&#x27;t really have clear documentation I can find anywhere about what specific criteria they use to make filtering decisions on 1.1.1.3 beyond that they &quot;aim to imitate&quot; Google Safe Search. Would people tolerate that kind of fuzziness if they were filtering hate speech or political extremism?<p>There is a reasonable debate people can have about whether or not it&#x27;s appropriate for Cloudflare to be the company that carves out sections of the Internet that are inappropriate, even as an opt-in filter. I think both sides of that debate can make some good points, and reasonable people could go in either direction. But for me, the biggest question isn&#x27;t really whether Cloudflare is the right company to build and maintain Internet filters. For me, the biggest question is about which subjects Cloudflare views as OK to moderate, and which communities Cloudflare is OK offloading the externalities of their moderation onto.<p>Because frankly, in free speech communities we do have a lot of hypocrisy about this. There&#x27;s no argument to be made that extremist hate sites aren&#x27;t just as dangerous to kids as pornography is. We should try to have more consistency about stuff like this. Are we OK with content moderation or not?
评论 #29037735 未加载
评论 #29037643 未加载
aayalaover 3 years ago
Unbound and root.hints
a10cover 3 years ago
any ideas why 1.1.1.2 doesn&#x27;t support tls?
评论 #29035720 未加载