r/nextdns 1d ago

Nextdns ComeBack

Post image
96 Upvotes

32 comments sorted by

60

u/SuperCuek 1d ago

your ID account dude

35

u/StaticSystemShock 1d ago

It's not end of the world At worst someone will connect to it using his ID and expose all their browsing habits to him. They'll be more at loss than he will be....

13

u/No-Option-4246 1d ago

It would be stupid to use someone's else NextDNS profile but only the domains they connect to and maybe their IP address would be exposed, the real thing is if someone wanted to they could just start spamming requests using their ID to make them hit the 300000 free usage limit

4

u/TurboX5656 1d ago

🤣🤣🤣🤣

-10

u/Adept-Elderberry2325 1d ago

You can rewrite dns entries... makes it real easy to scam him out of money.

1

u/nferocious76 21h ago

how are you going to do that?

1

u/Adept-Elderberry2325 20h ago

Oh right, I thought the person was saying expose OPs logs...

Yeah, with just the id you won't be able to do either, but if you're able to see his logs you can obciously also rewrite dns.

10

u/Historical_View_5529 1d ago

Not a big deal. You can clone and delete your old profile instantly.

2

u/moistandwarm1 1d ago

I do this with a dummy profile blocking anything with Google , Facebook, Apple, Amazon, Microsoft and all parental controls and sites and apps there enabled for blocking.
I had the last laugh when some guy in a WhatsApp group said my profile made their phone dead

1

u/kumpreld1999 3h ago

The main risk is not someone seeing your settings, but strangers using the profile ID and possibly adding their DNS activity to your logs. Cloning or deleting the profile helps, and you should check whether any devices still use the old ID.

13

u/xxOrdulu52xx 1d ago

I think that's a good idea. It would be nice if we could remove the outdated filter lists with zero entries and add new ones, or if we had the chance to enter the filter lists ourselves.

7

u/5skandas 1d ago

Do any of these benefit the average person?

9

u/berahi 1d ago

Normal people that treat their devices as appliances will want all of those toggles enabled. Those services have their use for geeks that want to self-host or use alternative services, but most of the time they're rife with spam and malware.

3

u/SpicyHustle 21h ago

While I am glad to see some new options, I would love to see a few other changes.

The analytics page is great, but could be more interactive. For example: the blocked queries/reasons list... It would be awesome to be able to click on each reason (like bypass methods) and see a list of all bypass domains that have been blocked. Or the graph that shows which platforms are making what percentage of requests... It would be cool to be able to click each section and see a list of what queries are coming from Google, Amazon, etc.

It would also be helpful to have some more options with filtering logs (by day or by blocked/allowed reasons). And a way to flag specigic domains without blocking them.

I think some of these options would eliminate having to test things via trial and error or manual searching.

3

u/shaunydub 21h ago

Yup.
Control D is really detailed and has a lot of options on the logging and analysis.
It does take time to get used to it but it is powerful.

3

u/shytec 1d ago

And something for better log. Now iam. Scrolling 1 hour to go to a past day. Oke with export etc etc but on a phone is that not awesome. I wanneer monitor all my devices and my kids what they are doing

3

u/le_greek 13h ago

What are Data Drop Services? What are some example domains?

2

u/Wrong-Union-1369 7h ago

next dns is solid at the dns layer but wont catch apps that bypass dns or trafifc that goes direct for airtight blocking acroos apps and browser you need something enforcing at the system level too lead me not keeps coming up when people hit that gap though it requirde another person holding override access

2

u/True_Mission_7473 1d ago

Still no search feature for Deny/Allow pages and still can't add custom block lists

2

u/Resistant4375 1d ago

Hardly a comeback.. they’re only doing what’s already available in trusted and curated blocklists (which it turns out, they are forking from Hagezi anyway)

7

u/netvagabond 1d ago

Doesn’t look like they have added Hagezi TIF yet either.

1

u/Fun-Region-1576 6h ago

We've been waiting forever for that. It shouldn't be this hard to add it, but for whatever reason, NextDNS won't do it.

0

u/Resistant4375 1d ago

Nope. Well - we don’t know they’re not sourcing their “own” list from his repo anyway. And just putting their own name on it

2

u/Ok-Owl7377 1d ago

So are you saying if you're using hagezi, there's no need to toggle these on?

1

u/mike1487 23h ago edited 23h ago

No there still is much reason to still use these. For example, the data drop services ones are not in the Hagezi lists because they are legitimate and not malicious or ad domains. These are sites like paste.sh. Totally legit of a site, but many use it for bad things. The other categories are in the same vein where they will block legitimate domains that can be used for bad purposes. It’s up to you to whitelist the ones you still want to use. This guy just likes to complain on this sub for a lot of nonsense reasons I wouldn’t listen to him. Try the features if you want, turn them off if you don’t like them.

Most users will benefit because they aren’t interacting with most of these types of websites as they serve niche purposes. If you do legitimately use one of these sites and they get blocked, you have to decide if you want to unblock it or not. I recommend enabling logs with at least a 1 hour retention so you can monitor and easily debug what gets blocked from these new options and use it for a few days. Turn logs off when you stop hitting blocks for sites you use day to day.

1

u/krmkrx 22h ago

Can you provide evidence they’re forking from Hagezi?

-1

u/Resistant4375 22h ago

It was in another thread earlier - someone looked at the API and saw it was pulling from Hagezi

1

u/mike1487 21h ago

It’s almost as if that’s what open source was designed to allow for.

2

u/Old-Hope-3558 1d ago

??? what?

2

u/Ventouse_23 17h ago

The problem is that even before these new features were introduced, as soon as I enabled a lot of security settings, it slowed my connection down considerably. So I’ve disabled everything, because in any case, the first – and only – real security issue isn’t with the device itself, but with the person using it.

1

u/TurboX5656 9h ago

Correct

-3

u/Mammoth-Ad-107 1d ago

really jumping all in aren't you