logoalt Hacker News

M95Dtoday at 7:19 AM1 replyview on HN

Yes, PiHole is the most common, but malware can easily bypass that using shared domains, P2P or IP addresses directly.

Use a filtering proxy instead and no gateway / route to the internet.


Replies

chupasaurustoday at 4:15 PM

1) Dnsmasq, you don't need the whole PiHole for that.

2) You're advising security through obscurity instead of a network namespace + firewall.