• 3 Posts
  • 128 Comments
Joined 2 years ago
cake
Cake day: February 13th, 2025

help-circle
  • Waterwolf I have found removes a lot of the Google bloot that is in Firefox.

    For 100% of people who use the internet, for the love of glob either turn off ssh or change the port number! Unless you have a setup for crowdsec, than have one pi or some other SBC with port 22 open.

    So for the 99% of people who want to feel as if there are no ads on the internet Waterwolf and uBO is enough.

    For the 99% of people who want to block ads and trackers on all devices, in most instances, there is all of the above plus pihole with unbound and a secondary pihole and that will be good enough. And for the love of glob they do not have a “smart” TV attached to their LAN even if it is on its own vLAN.

    For the 99% of people, without a static IP, who do not want to feel targeted using searXNG and the above things is good enough. People with a static IP a lot of the search engines rate limit you or just block static IPs from using their API.

    For the 99.9% of people who do not want to get, much, spam and block tracking pixels there is all of the above with your own email service, self-hosted (if they are crazy) or hosted with their own domain, with a new address for everything. This can also be used for unlimited free trials but I have only repeated free trials 2 or 3 times! I personally have a wild card setup with my current host so I get the occasional spam email just from bots who randomly find my domain and try to send it something. When that happens I block the address, occasionally domain, from sending me stuff and block anything sent to the address they sent it to. My previous host gave me unlimited emails for some ungodly amount of money and no wildcard so I had to sign in and manually create a new email address for everything sure I did not get the random fishing email sent to a random address but I had to actually plan on giving out my email before hand.

    For the 99% of people who want to feel safe on the internet there is all of the above plus OpenWRT, vLANs, etc.

    For the 99% of people who want to feel the warm embrace of that security on their LAN there is Wireguard, or something similar that is FOSS, to VPN into their LAN.

    I do agree with you that for the 99% of people a uBO, pihole, and router level VPN is enough, I do disagree with pointing to Quad9 is the right answer it should be going to Unbound first. I personally do not use a router level VPN for outgoing traffic because there is no FOSS thing other than TOR and right now I do not have the money for one. I guess I am in the 1% ish of people?









  • Before I fully understood what pihole was doing, it does not block out going things, it was amazing to see how much ad poop was trying to get to my TV. As I got more and more into this very inexpensive hobby of home labing /s I decided just to remove the TV from my wifi and my pihole went from blocking in the high 60% range to something more like the mid 30% range.





  • I went the Flint 2 route, I do not currently need wifi 7 but I did flash it with vanilla Openwrt. With the clean vanilla OpenWRT I have added 2 VPNs, I am considering adding a third (one is personal, one is to show off to friends, and the third one will be for my off site back up). I have a poop load of vLANs (IoT stuff, home lab stuff, my personal stuff, guest stuff, child safe vLAN, Personal VPN vLAN, guest VPN vLAN). I have a bunch of wifi APs, (personal, guest, kiddo safe, IoT, and a few because I am an asshole and believe all them waves belongth to me!).

    My plan was to host my own email server but this girl loves her hair and did not want to pull it all out, so I just continued on using a third party for that, this is why I got a firewall I controlled because I needed static IP addresses for email but I would recommend getting one if you are adding your own firewall just to by pass everything your ISP is doing, I have fibre but even when I had DSL my ISP had to keep their modem in there, port 1 is just a dumb switch that goes to my firewall.

    Originally I had a VPN running on a pi zero 2 (do not do this it is not that great to do it), but now my Flint 2 takes care of it and I do not notice any slow downs when I am away from the LAN. As a Canadian my PM just recently said we are at war with the US, sure it is a trade war not a pew pew boom war but war non the less and as an ex-Apple fan girl I was already slowly moving my stuff away from Apple things and use a pi 4 for HA I have a pi 5 running a bunch of services including pihole, would highly recommend, I have another pi 5 running stuff, and a pi zero 2 running my secondary pihole. I would highly recommend pihole to anyone who is just starting home labbing or been at it for a while, there is some disagreement with people who use other ad blockers but I found pihole first and feel in love with it. You will be so glad to have a VPN with whatever ad blocker you choose (pihole). But getting a static IP is a good idea, sure there are hacks to get things working with things like duckdns.org, your own domain, or whatever else.

    You mention hackers and bots, I have crowdsec running on my firewall with things going to all my other devices and a honey pot on my pi zero 2, but my suggestion is if you do not want to set up crowdsec and just rely on the firewall make sure you use strong passwords, I have vaultwarden for those, and change your ssh ports on your devices and while you are at it do not use anything in the 8080 port range.






  • I have a flint 2 (glinet) as my firewall as well, I had read somewhere that I should install vanilla OpenWRT so I did (I have added stuff to it so I like coming up with different flavours when talking to people like rocky road). I have Caddy running in docker on a pi in my LAN I have a password file of some sort that Caddyfile references at the top. Don’t ask me how I formatted it because I do not remember that part but take my secondary pihole as an example of using a domain that cannot be reached, from outside of my lan.

    pihole52.reannlegge.ca {
        @allowed {
            remote_ip 10.0.0.0/8
        }
        handle @allowed {
            redir / /admin{uri}
            reverse_proxy http://10.0.69.52:31415/
        }
        handle {
            respond "Not available from this network" 403
        }
        import easydns_tls
        log {
            output file /var/log/caddy/pihole52.log
            format json
        }
    }
    

    While other places on my domain can be reach outside of my vLANs. I have to secure some things up as I found that my SearXNG is open to the WAN.

    Edit: looks like search.reannlegge.ca was available on the WAN if you where in Canada but I have changed that to only on my vLANs and VPNs


  • I got into self hosting because my place flooded and I was waiting on insurance and the repair people to fix give the go a head and then to actually fix my place I do not really go anywhere so I was fine with being blasted with ads when I was out of my home, until I caught myself watching ads to get extra whatever from a mobile game. I had a pi zero 2 (with a PoE hat) that was not being used for anything so I thought why not use it to host wireguard, I had looked at a few options for VPNs but thought wireguard fit my needs the best. It “worked” I do not know if it was just my copper internet speeds or the silicon in the pi zero 2 which slowed everything down but now that I have a dedicated OpenWRT firewall, fibre, and a static IP (well technically 2 I just do not use the second one because the weekend project of spinning up my own SMTP and IMAP server had me at the point where I wanted to pull out my hair), I have wireguard automatically turn the VPN on when I am away from my LAN. So I would only see the adds if I went on someone elses device.


  • I use easyDNS and they have a wild card option for their email, so I have a formula whenever I am signing up for something my email addresses are always nameofservice_funSaskathchewanwordplusthreerandomnumbers@reannlegge.ca. When I started this I was on hosthero and they use cpannel with no wildcard options you have to go in and create the email address before you use it. When I left hosthero, because they cost to much and are not the friendliest company to deal with I had something approaching 300 unique email addresses after 4 or 5 years because I did just not bother closing them after I continued using the free trial of whatever or just stopped the forwarding to my main email address or whatever email it needed to be sorted into.

    Now I just have everything automatically go into junk mail unless it is something I need than I make the effort to log into their easyMAIL web thingy and sort where it should go. I have it set to delete things that are a week old (I think it could be a month?) so if I do not need it I do not need to worry about it and it will just go away on its own other things are sorted into folders and very few things are sent to my inbox.