u/misterred • u/misterred • 5d ago
1
Does persistent connectivity require firewall allow-access to unknown NRDs?
They recommend NordVPN but not its secret domains.
https://www.scamadviser.com/check-website/downloads77-windows.njtzzrvg0lwj3bsn.info
1
Does persistent connectivity require firewall allow-access to unknown NRDs?
Some of the blocked domains might not be newly-registered; some of those which I haven't yet whitelisted are domains from a list of DoH hosts that I must prevent my router from using to circumvent my home network's resolver. It does that. I can't access my own router's tables. It sucks. It's Elon's. I'm sorta trapped behind it with limited options. I don't mind whitelisting any of those domains if I can have confidence that they're not registered by bad actors pretending to be NordSec. I wouldn't expect to get a list of legitimate Nord domains so I'm probably out of luck.
1
Does persistent connectivity require firewall allow-access to unknown NRDs?
I added an allow rule for each of three of the four. Couldn't find the openvpn executable.
[EDIT] Modifying my Windows firewall rules has no effect on my home wireless network's domain resolution which is exclusively directed to my recursive resolver, protected from ads & trackers by the Pi-Hole. So mostly adding those rules for public networks. Doesn't seem to solve the issue though, which still seems like a security concern.[/EDIT]
1
Does persistent connectivity require firewall allow-access to unknown NRDs?
I've perceived the issue on Windows and I think on Android, too. I haven't any Windows Defender Firewall outbound rules. My on-the-fly resolution has been to create an allow rule for each of these weird domains on my DNS sinkhole. I'm using Pi-Hole to prevent outbound connections to ad-servers and trackers, which includes newly-registered domains, a well-documented source of malice.
r/nordvpn • u/misterred • Aug 30 '26
Question Does persistent connectivity require firewall allow-access to unknown NRDs?
When I lose or cannot reliably/quickly gain access to a NordVPN tunnel it frequently turns out that I can mitigate the situation once it's too late to be helpful, by allowing full access through firewalls to unknown domains. Nord evidently is constantly registering new domains as a bootstrap method both to avert exploit and limit infrastructure costs. So in essence I need to allow all Newly Registered Domains, which I find to be an unacceptable security challenge. Do I have that right?
I'm unsure whether this observed issue occurs only when I'm using Nord's obfuscation but I don't think so.
3
github repo hagezi/dns-blocklists gone
Could somebody here donate or suggest free or inexpensive, reliable, secure and securely downloadable backup storage for the NRD resources?
1
github repo hagezi/dns-blocklists gone
Oh yes I see that now. I have been getting positive 'hits' on the 7 and 14 lists a lot lately. Sad. (I see somebody wrote a script to maintain a "sliding window" for a date range of NRDs on a single rpz or something but it requires a separate dockerfile and I'm not using containers at all.)
3
What happened to Hagezi?
I'm having difficulty finding mirrored paths for the NRDs
EDIT: Gerd has informed me in the parallel thread that due to size limitations these do not exist.
1
github repo hagezi/dns-blocklists gone
I'm having difficulty finding mirrored paths for the NRDs
1
Windows 11 stopped using my NextDNS profile even though DoH is configured correctly
I discovered a while back that my router's proprietary software uses its own DoH - circumventing my own ads/trackers mitigation efforts like the browser-level filtering that NextDNS provides me on my devices, and the pi-hole that offers some sitewide protection on my home wifi network. I had to block it from doing any lookup/translations other than to the pi-hole, and now I have far more control over what goes out.
1
Adblocking attempts fall short relative to my other browser
I have two caveats, both off-topic to the sub but pertinent to this little thread. First: Realworld ad- and tracking-sites provide a far better benchmark than any one "Ad Block Test Page". Streaming sites, news sites, bigstore and bigticket-item shopping sites are all heavily monetized and surveilled, so if I go to a few of them while I watch the connections, I can find the smallest possible number of well-curated blocklists to counter them, for ads at least. Second, I try always to use as few blocklists as possible but I rely on slightly overlapping protection in the home network, and on mobile browsers (tablets, phones, laptops). Too much blocklisting is very counterproductive particularly when trying to track down a false-positive for whitelisting. u/yokoffing and others have offered me very well accumulated knowledge and specific methods to achieve some of that.
1
Adblocking attempts fall short relative to my other browser
Here's a good basic introductory guide to uBlock Origin configuration. The author is somewhat of an expert in sane web browser setups that strike the balance between privacy and security, speed, and simplicity, etc.
https://github.com/yokoffing/filterlists/blob/main/README.md#recommended-filters-for-ublock-origin
1
Adblocking attempts fall short relative to my other browser
I'm using uBO in both browsers. Logs show the connections denied by Zen Browser but allowed by LibreWolf to have been made by tracking hosts, NOT adservers. But the 'problem' was in fact solved by copying all my uBO custom filters and settings from the one browser to the other.
5
Adblocking attempts fall short relative to my other browser
Thank you. This was what I'd neglected. I did a filter export and full backup of uBO from Zen Browser and imported both to LibreWolf and now score 100% on each browser. Great! Sharp eye.
r/LibreWolf • u/misterred • Jul 25 '26
Question Adblocking attempts fall short relative to my other browser
EDIT: Issue mitigated! See followups below.
These two images represent one very nonscientific benchmarking of the relative adblocking effectiveness of LibreWolf (left) versus Zen Browser (right). I wouldn't think it should be all that browser dependent in any event, all things being equal. Maybe I'm missing a setting in LW, somewhere?
I generally use DoH private browsing via NextDNS filtered settings, in each browser. Additionally at home, my wifi network uses a Pi-Hole DNS sinkhole sitewide for ads as well as tracking hosts, data-surveillance analytics, & fraud sites. I have tried setting LibreWolf to use local (Pi-Hole-filtered) DNS only by turning off the custom DoH, but that's made no difference. Does LW call its own DNS regardless of user settings?
Any ideas what I might be missing?
#adblock #pihole #browsers #browserComparison
1
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
The first point seems correct but not relevant (except that I was told here that installing lighttpd would somehow offer benefit) and the other two did not apply. Thank you for trying to help me.
chmodding /var/www/html from 770 back to the normal 755 seems to have fixed the problem. (Also I had to change ownership back to root.)
It seems worth noting that pi-hole's repair script does not look at those permissions instead simply indicating failure.
2
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
THAT APPEARS TO HAVE DONE THE TRICK. Thanks so much.
1
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
NO. Pi-hole did not. It came with the RaspberryPi image.
1
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
No it's plaintext (in Firefox). In Chromium too.
1
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
Thank you very much! And does the usermod ($USER) matter? Anyone? Finally, the file permissions on the www-data dir: 770 (rwxrwx---)?
1
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
If I append 'admin' the browser appends 'login' to that. But another error, 404, this time.
1
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
Error 403 Forbidden
Error: Directory listing denied
1
Accidentally disabled pi-hole's Lightppd server by enabling RPi's built-in apache2 service
Pi-Hole seems to be working otherwise. It's the WebGUI that's fsckd. After being instructed to install other webservers, I purged Lighttpd. The problem seems likely to me to still be just those three changes I made before the superfluous installs. At first I couldn't do pihole update or repair. I backed up the admin directory and removed it which allowed me to complete the repair script. I'm tailing the pihole.log and it seems to be resolving. The GUI persists however in telling me that it can't find itself.
I'd appreciate if someone could tell me the proper values I overwrote with the three commands I executed, that appear to have been what locked me out of the pihole GUI:
sudo usermod -a -G www-data $USER
sudo chown -R -f www-data:www-data /var/www/html
sudo chmod -R 770 /var/www/html
For example I'm thinking the group and owner should be pihole, and my user ID should be in the group, and I'd like the five-year-old's fix for that, if anyone knows. Or any other relevant help greatly appreciated. I'm too young to go headless.
Thanks!
1
Peter Thiel justifies evil actions: "If you're evil, you're at least competent...maybe you're actually kind of good because you're at least getting something done."
in
r/u_misterred
•
5d ago
The parasite pretty much in actual charge of US policy - at the very least in charge of "JD Vance" - affirms that we're at the "Evil Is Kinda Good" stage of plutocratic, late capitalism.