I responded to someone in comments on a post that may not get as much visibility, and wanted to share something that might help some others who are newer to this.
I referenced Quad9 DNS as probably one of the best private DNS you can use, Swiss based, no log, no tracking, no data to sell, etc. They also implement DNSSEC, DoH, DoT, QUIC, ECS (which you may or may bot want), malware blocking, content filtering, and maybe something else I’m forgetting.
Many DNS sinkhole apps, OSes, or systems can actually utilize Quad9 for your resolver while those systems also block ads. Below is my functional list of systems that I’m aware of, though I haven’t tested everything. I believe all are considered FOSS, too. If you don’t have a spare Raspberry Pi laying around, try running in HomeAssistant, Yunohost, ZimaOS (previously CasaOS), or others.
DNS sinkhole (Adblocking) apps:
Feel free to comment and add your own I’m maybe not aware of. I’m no software engineer, but I can read through some code, though not an expert, nor have combed through these personally. Usually I’ve tested/run at the recommendation of others over the years before my ban on Reddit (for shitting on AI).
Hope this helps!!


Firefox with uBO behind a pihole pointing to Quad9 and on a router-level VPN is sufficient for 99% of users. And the 1% know exactly who they are and will harden further.
Waterwolf I have found removes a lot of the Google bloot that is in Firefox.
For 100% of people who use the internet, for the love of glob either turn off ssh or change the port number! Unless you have a setup for crowdsec, than have one pi or some other SBC with port 22 open.
So for the 99% of people who want to feel as if there are no ads on the internet Waterwolf and uBO is enough.
For the 99% of people who want to block ads and trackers on all devices, in most instances, there is all of the above plus pihole with unbound and a secondary pihole and that will be good enough. And for the love of glob they do not have a “smart” TV attached to their LAN even if it is on its own vLAN.
For the 99% of people, without a static IP, who do not want to feel targeted using searXNG and the above things is good enough. People with a static IP a lot of the search engines rate limit you or just block static IPs from using their API.
For the 99.9% of people who do not want to get, much, spam and block tracking pixels there is all of the above with your own email service, self-hosted (if they are crazy) or hosted with their own domain, with a new address for everything. This can also be used for unlimited free trials but I have only repeated free trials 2 or 3 times! I personally have a wild card setup with my current host so I get the occasional spam email just from bots who randomly find my domain and try to send it something. When that happens I block the address, occasionally domain, from sending me stuff and block anything sent to the address they sent it to. My previous host gave me unlimited emails for some ungodly amount of money and no wildcard so I had to sign in and manually create a new email address for everything sure I did not get the random fishing email sent to a random address but I had to actually plan on giving out my email before hand.
For the 99% of people who want to feel safe on the internet there is all of the above plus OpenWRT, vLANs, etc.
For the 99% of people who want to feel the warm embrace of that security on their LAN there is Wireguard, or something similar that is FOSS, to VPN into their LAN.
I do agree with you that for the 99% of people a uBO, pihole, and router level VPN is enough, I do disagree with pointing to Quad9 is the right answer it should be going to Unbound first. I personally do not use a router level VPN for outgoing traffic because there is no FOSS thing other than TOR and right now I do not have the money for one. I guess I am in the 1% ish of people?
Good point, but if I can help anyone with privacy or security, it’s a good starring point. Maybe a few more will get curious and go further down the rabbit hole lol.
Fair enough. I love the spirit of your intent. But we’re already wildly self-selecting for people versed in any level of opsec by just assuming they know how to SSH into a headless Pi if something goes wonky, plus know *NIX terminal commands.
I would say that for general users, switching to Firefox and getting uBO is enough. That much is very easily done by the layperson (and honestly would be sufficient for people looking at cat photos and reading email). From there, we veer off into needing technical skills.
Touche. Though, I’ll admit I use VNC to access my pi, not SSH. I’m not a terminal fan if I can help it. I mean, I guess I still use terminal once in, so, maybe I should use ssh. Hmm. I never gave it too much thought.