Security Pi-Hole

Moriath

I am a FH squatter
Joined
Dec 23, 2003
Messages
16,209
Just changed the way my two pi-holes stay in sync. Hopefully is a bit more robust than the old method.

Upgraded yet @Moriath ?
BC665CBF-0558-4DAE-B917-D97A63C7B83E.png
updated and all good :). Took me a bit to remember the root password to the ting to begin with haha. Im dumb with usernames and passwords. hate writing them down then 3 months later play guess the word
 

Moriath

I am a FH squatter
Joined
Dec 23, 2003
Messages
16,209
Use a password manager then like Lastpass.
Will it work for filing in ssh term passwords? I have last pass but only use it for the website stuff it seems to auto fill ... but then i have to remember my lastpass account too hehe
 

dysfunction

FH is my second home
Joined
Dec 22, 2003
Messages
9,709
Will it work for filing in ssh term passwords? I have last pass but only use it for the website stuff it seems to auto fill ... but then i have to remember my lastpass account too hehe

I don't know about that but you can at least look it up!
 

MYstIC G

Official Licensed Lump of Coal™ Distributor
Staff member
Moderator
FH Subscriber
Joined
Dec 22, 2003
Messages
12,379
I use Bitwarden. Used to use LastPass got fed up with it.
It is any better?

I used to have LastPass on Pro, then LogMeIn bought it and made it pointless to subscribe by making the mobile support free.

I dropped down without issue a couple of years back but just recently they've started adding in shitty "do you know about Pro" crap and I'm finding it works worse on Android than ever now
 

Deebs

Chief Arsewipe
Staff member
Moderator
FH Subscriber
Joined
Dec 11, 1997
Messages
9,076,937
It is any better?

I used to have LastPass on Pro, then LogMeIn bought it and made it pointless to subscribe by making the mobile support free.

I dropped down without issue a couple of years back but just recently they've started adding in shitty "do you know about Pro" crap and I'm finding it works worse on Android than ever now
I love it.

I self-host as well :)
 

old.Osy

No longer scrounging, still a bastard.
Joined
Dec 22, 2003
Messages
2,636
As we don't have an over-arching thread for Security related stuff, and as i'm lazy to open a new one (or search for it), I'll just relay here some stuff.

1. Android 9 and 10, enable secure DNS (DOH / DOT): Settings, Connections - More connection settings, Private DNS, select "Private DNS provider hostname" radio button and input 1dot1dot1dot1.cloudflare-dns.com (you could use other secure DNS providers, but unless you dabble in illegal stuff, cloudflare should suffice)

2. Android 4.2 and above, go to IngoZenz/personaldnsfilter - very nice tool, installation by apk file, quite straightforward. Does adblocking, outbound firewalling (can restrict apps/services outgoing), VPN, Secure DNS, you name it.

3. For even more peace of mind, you could use DNSCrypt - DNSCrypt - Official Project Home Page - pretty much platform independent.

4. Encrypted SNI (Server Name Indication - Wikipedia) is currently supported only by Mozilla nightly build for desktop.

I know some of you mitigate this for the home LAN directly at the router / pihole lvl, but when offsite the above applies.

Edit: depending on the browser you use at desktop level, enabling secure DNS may differ. You'll just have to google it :)

Edit 2: You can check whether you were successful with enabling Secure DNS, point your browser to Cloudflare ESNI Checker | Cloudflare
 

Jupitus

Old and short, no wonder I'm grumpy!
Staff member
Moderator
FH Subscriber
Joined
Dec 14, 2003
Messages
3,293
As we don't have an over-arching thread for Security related stuff, and as i'm lazy to open a new one (or search for it), I'll just relay here some stuff.

1. Android 9 and 10, enable secure DNS (DOH / DOT): Settings, Connections - More connection settings, Private DNS, select "Private DNS provider hostname" radio button and input 1dot1dot1dot1.cloudflare-dns.com (you could use other secure DNS providers, but unless you dabble in illegal stuff, cloudflare should suffice)

2. Android 4.2 and above, go to IngoZenz/personaldnsfilter - very nice tool, installation by apk file, quite straightforward. Does adblocking, outbound firewalling (can restrict apps/services outgoing), VPN, Secure DNS, you name it.

3. For even more peace of mind, you could use DNSCrypt - DNSCrypt - Official Project Home Page - pretty much platform independent.

4. Encrypted SNI (Server Name Indication - Wikipedia) is currently supported only by Mozilla nightly build for desktop.

I know some of you mitigate this for the home LAN directly at the router / pihole lvl, but when offsite the above applies.

Edit: depending on the browser you use at desktop level, enabling secure DNS may differ. You'll just have to google it :)

Edit 2: You can check whether you were successful with enabling Secure DNS, point your browser to Cloudflare ESNI Checker | Cloudflare

Very helpful @old.Osy , assuming accurate which I am :)(y)
 

Moriath

I am a FH squatter
Joined
Dec 23, 2003
Messages
16,209
As we don't have an over-arching thread for Security related stuff, and as i'm lazy to open a new one (or search for it), I'll just relay here some stuff.

1. Android 9 and 10, enable secure DNS (DOH / DOT): Settings, Connections - More connection settings, Private DNS, select "Private DNS provider hostname" radio button and input 1dot1dot1dot1.cloudflare-dns.com (you could use other secure DNS providers, but unless you dabble in illegal stuff, cloudflare should suffice)

2. Android 4.2 and above, go to IngoZenz/personaldnsfilter - very nice tool, installation by apk file, quite straightforward. Does adblocking, outbound firewalling (can restrict apps/services outgoing), VPN, Secure DNS, you name it.

3. For even more peace of mind, you could use DNSCrypt - DNSCrypt - Official Project Home Page - pretty much platform independent.

4. Encrypted SNI (Server Name Indication - Wikipedia) is currently supported only by Mozilla nightly build for desktop.

I know some of you mitigate this for the home LAN directly at the router / pihole lvl, but when offsite the above applies.

Edit: depending on the browser you use at desktop level, enabling secure DNS may differ. You'll just have to google it :)

Edit 2: You can check whether you were successful with enabling Secure DNS, point your browser to Cloudflare ESNI Checker | Cloudflare
Now produce an apple one ;)
 

Users who are viewing this thread

Top Bottom