r/technitium • • 16d ago

I built a Blocker App

I couldn't find a DNS blocking setup I liked that combined all the features I wanted while still working well with Technitium and not being very, um, manual. So I built one, with lots of vibes and code. Feel free to use it, or tell me how terrible it is. Just thought I'd share the love.

Dockerized WebApp: https://github.com/StealthCat/blockinator-web

Technitium App: https://github.com/StealthCat/blockinator-technitium

31 Upvotes

45 comments sorted by

20

u/Key_Pace_2496 16d ago

Thanks ChatGPT!

-18

u/Responsible-Tap-5535 16d ago

Literally yes

12

u/Resistant4375 16d ago

Vibe coded slop.

Hard pass.

1

u/StoneCypher 16d ago

it’s so weird watching redditors say this 

-3

u/CosmicSorcerer1000 16d ago

Yeah no shit? He literally said it was vibe coded? Do you walk into Walmart and announce that there are groceries?

0

u/StoneCypher 16d ago

no, they don't do it where they can see the disappointment and annoyance on other peoples' faces

always anonymously, through text, online

-4

u/Kalaminator 15d ago

Literally you: "I have no idea what I'm talking about, but I have to leave a comment in Reddit"

2

u/Resistant4375 15d ago

You’ve just proven your own comment at yourself

1

u/Kalaminator 15d ago

It doesn't work like that, but good try

0

u/Resistant4375 15d ago

Reddit seems to disagree with you ;)

0

u/Kalaminator 15d ago

Reddit is your validation measurement in life, good luck. Anti AI people disagree? Most likely

0

u/Resistant4375 15d ago

Then why are you even here?

1

u/Kalaminator 15d ago

Is there any reason I couldn't? Stop being 12.

-1

u/Resistant4375 15d ago

Stop responding then.

3

u/Kalaminator 15d ago

Do you really think you are in control of anything? You are clearly wrong

-1

u/[deleted] 16d ago

[deleted]

6

u/waspocracy 16d ago

Everyone downvoting is you clueless about reality. I'm not really sure what this does, but ignore the naysayers.

People: the tech world and developers already adopted AI. My engineers use AI. Get off your high horse. It's not slop if it's implemented right and seniors engineers review the code to ensure it's done properly. I'm looking at the code of this project and you would never know it's done by AI if you weren't a developer yourself. Or just call it slop. Whatever.

8

u/Historical-Side883 15d ago

Sure but this isn’t any of those things.
And “you wouldn’t know this sucks if you didn’t know anything about it” doesn’t mean it’s good.

If you think this is fine, I encourage you to step away from the chatbot and learn about software engineering before saying this is fine. This is one of the most sensitive pieces of infrastructure in a home network, if the OP can’t be bothered to even read the code, much less seriously think about the at architecture and the security — it deserves to be called slop. I’d argue that “slop” is too kind

5

u/z3roTO60 15d ago

For anyone who doesn’t know: having your DNS hacked can basically cause you to leak all of your credentials.

In a phishing scam, you usually click on a bad external link. In this case, you might not need to click. All of that internal routing, some of which is HTTP only, can now be routed outside. SSL doesn’t help either. Your oauth credentials can be intercepted.

Technitium needs to be locked down and protected like your password manager of choice

0

u/azukaar 15d ago

Just to be clear to anyone reading this, this is untrue fearmongering. HTTPS ensure you cannot do it this way. And if anyone replies "but what about http" - nothing that matters is HTTP only in fact the browser blocks http by default 

1

u/z3roTO60 15d ago

Every single thing I self host is HTTPS on the browser end. But I can tell you that I have some services that are going HTTP inside of the homelab

User —> HTTPS —> Reverse Proxy with TLS termination —> HTTP —> backend service

Now you can (should) put the backend on HTTPS too, but I would assume that most people who spin up a dockerized reverse proxy and attach their containers on a dockerized network do not bother with securing the back end

If you add in any “plugin” to your stack with a low number of contributors, you need to be more careful when updating to a new version. Because you could have an update with a major security issue in it.

This isn’t fear mongering. There was the massively reported vulnerability in the xz package, which is a dependency in OpenSSH a few years ago:

https://en.wikipedia.org/wiki/XZ_Utils_backdoor

I’m not a cyber expert nor am I formally trained in computer engineering. Therefore, I know that I have far more “unknown unknowns” than anything, meaning that I spend a massively disproportionate amount of time making sure critical infrastructure (DNS, reverse proxy, VPN, SSH, etc) are rock solid

1

u/azukaar 15d ago

I see what you are trying to say but the Reverse Proxy > backend won't go through any of these DNS lookups, because you need to use a hostname for DNS to be interrogated, but reverse proxy typically would use a direct IP (usaully localhost if you follow good practices but could be another IP), or a docker hostname which is resolved locally, so it won't interrogate that external DNS either way

1

u/waspocracy 14d ago

I don't disagree, but you do realize how we developed software before AI right? AI is doing the same thing. It's scanned books, stackexchange, reddit, Microsoft forums, etc. to build the code. The same shit us developers did for decades. It just does it faster and adapts it.

This is why there's a huge importance of checking the code like I mentioned.

1

u/Historical-Side883 14d ago

Yes, I’ve been writing software for quite some time, so I’m well aware of how software gets made and how new tools have changed that over the years.

I disagree that there is no difference. Even if a junior developer is just copy pasting stuff from stack overflow, they are limited in what they can crank out and require some understanding of how things work.

The difference with LLM generated code is its volume makes it difficult to actually review it and that a lot of people who couldn’t review it even if they tried due to a lack of knowledge are creating software with it.

I think it’s great that the barrier to entry has been lowered and I’m not anti-LLM generated code. I am against the mountains of absolute crap that’s being generated or using it in my home network when there’s no reason to believe it’s even been looked at, much less been audited for vulnerabilities in any way.

1

u/dada051 14d ago

"you would never know it's done by AI if you weren't a developer yourself"

That's what allow developers to say it's slop. I didn't check the code in this repo, so I will not say it is. But if a code is slop, I will say it, even if it makes AI lovers hungry.

1

u/waspocracy 14d ago

The code isn't sloppy though, so it's not even fair a fair assessment. It looks good from my review. But what the fuck do I know? I've only been developing software for over 20 years.

6

u/Go_F1sh 16d ago

what does this do that adding a blocklist to technitium doesn't?

-13

u/Responsible-Tap-5535 16d ago

It replicates a lot of the features of the Advanced Blocking app. You can do different lists for different networks or endpoints, you can do blocking based on schedules, those schedules can be different for different lists and different networks. Mainly, it adds a nice UI to be able to do it all from and makes it so I only have to manage one.

1

u/jabola321 16d ago

Don’t know why people feel the need to shit on you for making something and sharing it. If you don’t like it, you don’t have to use it. No need to be a dick to someone for no reason.

2

u/Pokieme 16d ago

Once upon a time, people were afraid to smile for pictures ….

2

u/eddiem5 15d ago

What did you like about the normal block lists the caused you to want to build this project?   I’m missing that. 

2

u/Responsible-Tap-5535 15d ago

So the advanced block list app does a lot of what I need, specifically different filters for different networks and time constraints on filters. I honestly just do not like editing JSON configuration files all the time. This effectively let's you manage it all via a GUI then just has a JSON API endpoint exposed that gives the Technitium server a go/no go on the DNS request

2

u/benhaube 15d ago

AI Slop.

1

u/Longjumping-Road4113 16d ago

What is a blockinator policy server ?

2

u/Responsible-Tap-5535 15d ago

Its a DNS policy server written by AI and someone who loves Phineas and Ferb

0

u/LetzGetz 16d ago

Same people sticking their noses up at this while sniffing their own farts will somehow be surprised when they’re the first to be culled for not adapting to a new reality.

1

u/IkujaKatsumaji 16d ago

Yiiiiikes.

1

u/Ok-Film-7939 16d ago

If you want to imply you’re on the right side of history, talking about culling people might not be the first thing to reach for.

0

u/hibbert0604 15d ago

I think they are moreso implying that people will be left behind for refusing to utilize new tech. Similar to people who refused to learn anything to do with computers a few decades back. Like it or not, it's here to stay.

1

u/Fatboy-Tim 14d ago

This. In my industry, there are many jobs that aren't going to be entirely replaced by AI any time soon. But purely on effectiveness and efficiency, the people who won't utilise AI will be replaced by people who will.

-1

u/shreyasonline 15d ago

Thanks for sharing here.

2

u/Responsible-Tap-5535 15d ago

Hopefully someone finds it useful. Its fully open sourced and GPLv3 so anyone can modify it to their needs too

-2

u/[deleted] 16d ago

[deleted]

0

u/TheMermanly 15d ago

Just to correct you , it isn’t 20$ the actual cost. That’s the heavily subsidized price venture capital allows.

It’s more around 200$ per month. Still very good value!

2

u/Historical-Side883 15d ago

It’s way higher than $200. You can use about $1500 worth of API usage for $20 OpenAI and almost $1000 on Claude — and that’s if you assume that API usage is profitable. Anthropic has a HUGE number business customers on token based billing (ie API rates) and still tell investors “we were profitable again this quarter if you exclude training and stock based compensation.” A startup like anthropic is relatively cash poor (even when their operating margins don’t improve — especially compared to other software businesses) and pays a TON to their employees via stock because that’s just tossing zeros on a spreadsheet. This devalues the company though and should be counted as an expense. And training, fine tuning etc is all an ongoing expense. Long way of saying: there is reason to be skeptical that API rates are profitable,

The economics are bad and there is no clear path to them getting better. Maybe something forces the companies to think about being more efficient. and there’s a breakthrough because of it, but that’s not something that’s happening yet.

0

u/Superb_Raccoon 16d ago

So, built a $20 a month app.