ah, dnsmasq... the "gift" that keeps on giving. the project hasn't been given consistent love from maintainers for reasons and router vendors are infamous for shipping really bad versions and not updating...
when i was at a large ISP in the DNS team, we used to get called into outage meetings and the first assumption everyone always made was that any problem must be DNS until we'd proved otherwise.
turns out that pretty much all the time, get packets to pass reliably was the problem, which broke everything including DNS.
we had patches and stickers made with "!L3 == !DNS".
- systemd-resolvd - your router gets default resolver from upstream and that was missing/wrong/pointing to broken resolver, borking DNS for local network getting DNS to use from DHCP lease - something in /etc/hosts - not putting something in /etc/hosts
twice the evil. spam trying to convince me that my chatGPT subscription (which i wouldn't take at gunpoint) isn't processing and i need to give them my credit card. sigh...
bwahahahahahahahaha... GOP tone deafness and hypocrisy hitting new lows...
boebert, kicked out of a children's play for being high and feeling up her date while the play was going on, is going to judge folks for sexual misconduct.
i do blocking in my house but of a very small set of FQDNs. all are known ad brokers or malicious C&Cs. makes browsing vastly faster and i don't miss out on anything. i also do various other things but that blocking is a useful bit. it's definitely not a full solution in any sense. defense in layers.
an informed choice about who you get to filter your DNS, including making sure it's a well curated and frequently updated block list, can be a feature in your security profile. but the end user must be the one to decide, not some IP/copyright owner on a tear or some politician with as little understanding of security as of brain surgery.
it's not just a blunt/crude tool to do this. it's a mostly ineffective tool. it breaks things way more often than it does what is intended. it's playing russian roulette with 5 bullets and one empty chamber.
i have unique emails for every vendor i deal with. i just got spam to a phone company email that i haven't needed or used since 2005. so, this telco kept a 20 year old email and failed to secure their customer PII. bravo...
Just trying to spread the good word about IPv6. Member of an obscure technical group on the internet. Still remember when it was all the ARPANET. DNS/DNSSEC.Love pretty much any musical instrument with strings and frets (and a few with just strings). Play/build/repair as many of them as I can.Profile picture is a 1924 Gibson F-4 mandolin with a Virzi tone producer.i do screen followers. if you are brand new, don't have any useful bio, or posts, generic avatar, etc. i will probably deny your request.#guitar #mandolin #bass #music #cocktails #cooking #kumihimo #BadPuns#SlavaUkraine #BlackLivesMatter 9X#CovidBoosters