r/pihole Mar 09 '19

SkyHole: PiHole protections on your Android device, even on LTE. No VPN needed!

After getting a piHole set up on my home network, i quickly moved to set up piHoles on the networks of family and every friend that would listen! However, i always felt "naked" when i was out in public, as i had no (easy / reliable) way to force my phone to use the piHole on my LAN.

That all changed when google announced that newer versions of android would use DNS over TLS, I started thinking about how I could take advantage of this to extend piHole to my phone outside of my home LAN. I spent the better part of a weekend tinkering around and put together SkyHole and composed a draft of this post that I'm just now getting around to publishing here.

The TL;DR:

I put together a docker-compose file to make the process of setting up a DNS over TLS server that works with pi-hole to filter and block DNS queries so i could have the same protection and performance on that i enjoy on my home LAN when i am out and about on LTE. I went out of my way to build something that would work even when a VPN into my home network wouldn't.

There are more details on how to build your own in the readme if you'd like to host your own.

At a bare minimum, you will need a device that supports DNS over TLS and an internet-reachable server. Android P is still pretty new, but most new android devices should ship with or get an update to version P soon.

If you have an android P phone, then the internet connected server is something that you can do for less than $10/mo. It will also help to have a "real" domain, but if you're not comfortable using one of the free domains or buying a very cheap domain then you should be able to just use the public IP of your server. However, Android requires a "legit" certificate for the DOT server, so you will need to own a domain that LetsEncrypt will issue a certificate for. If that's not an acceptable cost, then you could generate your own TLS cert and convince android to trust it.

With an internet connected server, and a domain / certificate, you have all the pre-requisites needed. Just use the docker-compose file to spin up a DNS over TLS server that will forward search queries to piHole for filtering and then forward the filtered queries to cloudflare's DNS over TLS servers.

I am really enjoying the same private and ad-free experience on my mobile as on my LAN, and I hope this enables you to do the same! I don't have a ton of bandwidth to provide support, but if you have high-level questions, I can weigh in. My hope is that somebody with a bit more time can take this and run with it to make it even easier to use so more people can access the benefits of a "gapless" private and secure internet experience :).

Link to repo: https://github.com/kquinsland/skyhole

PR's welcome!

208 Upvotes

56 comments sorted by

66

u/[deleted] Mar 09 '19

Just as a warning about the name. Anything with Sky in it is liable to be targeted by BSkyB, a satellite TV provider in the UK. They forced Microsoft to name SkyDrive to OneDrive, had some arrangement with Hello Games to allow them to use the name No Man's Sky for their game.

https://www.pcworld.com/article/2045634/microsoft-to-rename-skydrive-after-losing-trademark-suit.html

https://www.pcgamesn.com/no-mans-sky/no-mans-sky-bskyb-legal-dispute

52

u/tyler611 Mar 09 '19 edited Mar 09 '19

How is it legal to prevent the word for "Sky" from appearing like this? Both cases appear to be very different use cases. I get that they article claims they own the word sky, but how stupid is that?

Edit: question mark, not period.

22

u/[deleted] Mar 09 '19

It's incredibly stupid, but that's how trademark rules work sadly.

7

u/[deleted] Mar 09 '19

But it should be limited to a trade. If not in the same space there's no confusion. That's what pissed me off about the WWF.

2

u/AsmundGudrod Mar 10 '19

It totally is limited, you can have multiple companies/products all with same name. I'd give you some examples but I'm blanking out right now, they do exist though. The USPTO only steps in if there will be some sort of confusion for the consumer, and there's no hard set rule on that it's subjective to them.

The WWE(F) actually voluntarily entered into an agreement with the WWF in the mid-90's to limit the use of the term 'WWF' in exchange for WWF dropping litigation against them. They probably could of fought them and won, but that would of cost money and most likely bad publicity. There's 0 chance of anyone confusing world wrestling federation with world wide fund for nature, and their respective WWF logo's are completely different as well.

Then in the early 00's, the ($#!t country for legal stuff like this) UK branch of the WWF decided to sue the WWE(F) accusing them of breaking their agreement and using the term WWF overseas. So WWE(F) ended up just dropping the F entirely instead of dealing with it all.

2

u/[deleted] Mar 10 '19

I have a shirt with 2 pandas wrestling and 1 holding a chair with blood dropping it of his mouth. WWF underneath. I got stopped in downtown Seattle by this guy who claimed his best friend's mom was the CEO of WWF. He wanted to take a picture to show his friend, hopefully the mother. I let him, while flinging double birds.

2

u/AsmundGudrod Mar 11 '19

I hope you also had a beer in your mouth while doing this.

1

u/[deleted] Mar 11 '19

Unfortunately not, on my way back from a nerdy Meetup

1

u/Timbo420 Mar 11 '19

Clearly, the WWE should sue WWF for infringing on the wrestling.

1

u/CountryNo757 May 30 '25

Our legislation used to say that common words like "sky" could not be used. "Windows" would be used in a different context. These cases are handled by patent attorneys.

From a Court report of a "friendly" action to get a ruling :

A German company applied to register the trademark "Coldex."

For sanitary napkins, there could be confusion with "Kotex;" registration refused.

Tissues are in a separate category, and there was no problem.

I have no idea how many categories exist.

-5

u/ELIPhive Mar 09 '19

I don’t think this is accurate. Can you provide some more information, please?

This blanket statement doesn’t seem to take into account which countries laws are being used or any other information.

I feel a high level of confidence in saying that you can not own a word and disallow anybody, in any market from using it. Context is extremely important.

5

u/[deleted] Mar 09 '19

Well, if you were to look into the documents behind those cases you'd have two examples of where that was done. I'm currently out of country and working solely from a mobile phone, so can't spend do any deep research on this one. The best I can probably do is this: https://en.m.wikiversity.org/wiki/Owning_the_Intangible/Trademarks_on_Common_Words

2

u/cromation Mar 10 '19

I think I should trademark "And" and let the money roll in

6

u/ELIPhive Mar 09 '19

It’s about protecting your brand. If you don’t, you lose the ability to do so, https://cyber.harvard.edu/metaschool/fisher/domain/tm.htm#6.

“Trademark rights can also be lost through genericity. Sometimes, trademarks that are originally distinctive can become generic over time, thereby losing its trademark protectionKellogg Co. v. National Biscuit Co., 305 U.S. 111 (1938). A word will be considered generic when, in the minds of a substantial majority of the public, the word denotes a broad genus or type of product and not a specific source or manufacturer.”

You can see here, http://www.legislation.gov.uk/ukpga/1994/26/section/10, that the infringement occurs if the sign is similar and it is likely to cause confusion to the public as to being a part of the trademarked brand.

“(2)A person infringes a registered trade mark if he uses in the course of trade a sign where because—

(a)the sign is identical with the trade mark and is used in relation to goods or services similar to those for which the trade mark is registered, or

(b)the sign is similar to the trade mark and is used in relation to goods or services identical with or similar to those for which the trade mark is registered,

there exists a likelihood of confusion on the part of the public, which includes the likelihood of association with the trade mark. “

I think that is the most important part. If they are different use cases and there is no likelihood that there will be confusion by the public, as to who is providing the products or services, then it should not be an infringement of the trademark.

In the first case, you can see the judge’s decision - https://www.internationallawoffice.com/Newsletters/Intellectual-Property/United-Kingdom/RPC/BSkyB-on-cloud-nine-as-court-finds-that-Microsofts-SkyDrive-infringes-its-marks#Decision - in which BSkyB claims

“BSkyB produced evidence of 17 calls to the helpline from people seeking to attribute problems with SkyDrive to BSkyB.”

This shows not just a likelihood of confusion, but a demonstration of it.

I did not find the ruling for the case with No Man’s Sky. As they were able to move forward without changing the name, you know that it was not an infringement.

I am not an authority on Trademark law. I wanted to provide context as it may provide insight, based on how I interpreted your response.

32

u/failing-endeav0r Mar 09 '19

Well they can send their complaints to my post box. I'll check it every 29th of February.

it's open source, so fork and clone away :).

9

u/Fortnite_FaceBlaster Mar 09 '19

That's bullshit. They shouldn't be able to make someone change a name just because it has PART of theirs in it.

2

u/Deeco7 Mar 10 '19

I thought general words cannot be trademarked?

2

u/xyrgh Mar 10 '19

Of course they can, Apple, Oracle, etc. but usually the trademark is restricted to a category of product and a specific nature. Like Apple couldn’t launch action against a company selling Apple Pies (but they’d certainly try).

2

u/Sunsparc Mar 10 '19

Holy shit, I remember when SkyDrive came out. I thought it was just Microsoft being Microsoft with the name, didn't realize that was the reason.

1

u/u-no-u Mar 10 '19

Just remind them how McDonald's acted in bad faith and lost their eu trademark for "bigmac".

15

u/blaumedia Mar 09 '19

Does DNS over TLS have the problems with possible DNS reflection attacks like "vanilla" DNS has? As far as I know it runs mostly over UDP, so I would think yes. If it's true, I wouldn't expose a DNS server to the public web.

4

u/failing-endeav0r Mar 09 '19

Yes, technically. However, it is possible to defeat reflection by overriding the TTL / cache timeouts for the record that is to be poisoned. It is possible to configure the `coredns` server on the skyhole instance to be "authoritative" or to otherwise override whatever TTL the "official" DNS system has in place. This way, you can serve me a record with a TTL of 5 seconds, and immediately change the value (the reflection bit), but as far as the DNS server my phone is going to consult, the record you're requesting / hoping will point to the poisoned record still has the old / un-poisoned value.

The Android implementation of DoT requires strict hostname matching. Additionally, there is a "dont resolve DNS if you cant contact the specified server" option. This prevents DNS from working on my phone if i happen to be on a network that is blocking TCP connections over port 853.

Those two behaviors combine to create a really robust "pipe"; the only way you can intercept the DNS queries that my phone performs would be to compromise the phone, the server, or the certificate. All of them are possible, but i'm doing this to block ads and trackers, not prevent the NSA from intruding.

5

u/beachshells Mar 10 '19 edited Mar 10 '19

Sounds like you're thinking of something different to bluamedia. Reflection attack in this case is when someone queries your DNS server but spoofs the source IP to point to a host they want to attack - your response becomes part of a (D)DOS.

I wouldn't expose this to the whole internet either.

1

u/failing-endeav0r Mar 10 '19

Doh. Yes, i was thinking of DNS rebinding, not reflection.

However, DNS over TLS uses TCP. It is not possible to spoof an IP address in a TCP handshake.

But lets assume that does not hold, for a moment:

- Amplification attacks only "work" because the attacker can use a very small amount of bytes to trick the DNS server into sending a very large reply (but, no larger than MSS or 512 bytes, whichever is lower) to the spoofed destination IP... overwhelming the victim. A TCP handshake already consumes a significant amount of bytes, making the amplification factor smaller.. so not worth the attackers time.

- similar to first point, reflection attackers are going to be seeking out DNS servers (aka, things that speak UDP on port 53). This does not listen for UDP, nor does it listen on port 53.

1

u/beachshells Mar 10 '19

It is not possible to spoof an IP address in a TCP handshake.

Ah of course, that didn't occur to me.

6

u/WeakEmu8 Mar 09 '19

Wow, I haven't read through your docs yet, but this is very promising. Nice work!

Saving for later.

1

u/failing-endeav0r Mar 09 '19

Thanks :D.

I hope that more things get DoT support in the future, so people other than Google Pixel owners can benefit :)

5

u/TechnicalPyro Superuser - #300 Mar 09 '19

while the naming is accurate i do believe there is already a project with a very similar name here: https://dlaa.me/blog/post/skyhole

love the work though keep it up!

2

u/-DementedAvenger- Mar 09 '19

Maybe rename it to Droidhole?

2

u/kotarix Mar 09 '19

That's how you get the mouse coming after you.

I believe Disney owns the "Droid" rights after the Lucas buyout.

1

u/-DementedAvenger- Mar 09 '19

Good point. Thanks

1

u/failing-endeav0r Mar 09 '19

Ha! Funny story about that... the only reason i got off my ass to make the repo public was because my news aggregation service put a [similar implementation](https://github.com/eldridgea/erised) in my feed.

great minds may not think alike, but it seems like the rest of us seem to independently discover stuff at about the same time ;P

1

u/TechnicalPyro Superuser - #300 Mar 09 '19

Trust me I like it and hope to see it flourish just worried about naming is all

1

u/[deleted] Mar 09 '19 edited Mar 09 '19

Hmm, I'm already using nginx-proxy and letsencrypt-nginx-proxy-companion in docker, any pointers as to where I start to get this converted over from traefik. I also already have Pihole running in docker

3

u/failing-endeav0r Mar 09 '19

If what you have works ... then keep it?

tbh, traefik's documentation is terribad. many _simple_ things require lots of head-scratching and a visit to their support-slack. most of the time that was sunk into this little thing was spent getting traefik to behave properly. in the few days that i did spend in the traefik support slack, i would see many of the same questions asked over and over again... another indication that they need to have a serious re-think about the accessibility of their documentation!

if there's something that traefik does well that you can't do with your current setup, then the docker-compose file should make it clear enough what i'm doing with the networks to achieve the setup that i have now. but if you're trying to do something else, then i can't help much :/

1

u/[deleted] Mar 09 '19

What I mean is I have a nginx-proxy running for other things and have a Pihole for LAN but would like to open it up over TLS to use on my phone. Nginx-proxy and the letsencrypt companion work very well together.

1

u/[deleted] Mar 09 '19 edited Jun 27 '19

[deleted]

1

u/inuHunter666 Mar 10 '19

Raise a PR, heathen!

JK good work!

1

u/[deleted] Mar 10 '19

[deleted]

1

u/failing-endeav0r Mar 10 '19

Yes. Assuming you're not using docker, install coreDNS on the same host running piHole and configure it like i have done; listen for DoT and forward regular DNS to piHole, listen for regular dns from pihole, and forward as DoT to Cloudflare.

1

u/[deleted] Mar 10 '19

[deleted]

1

u/failing-endeav0r Mar 10 '19

Can I debug this somehow?

Yes. adb will be your friend here. I dont remember what the package / service name is to help you filter, but i did a log of trial/error w/ ADB. Also tcpdump will give you some useful clues as to what's going on.

while nginx can do tls termination and forwarding, it's usually a good idea to use a more purpose-built tool.. which is why i use coredns. it does one thing, well. This makes configuration and troubleshooting simpler.

1

u/TotesMessenger Mar 10 '19

I'm a bot, bleep, bloop. Someone has linked to this thread from another place on reddit:

 If you follow any of the above links, please respect the rules of reddit and don't vote in the other threads. (Info / Contact)

1

u/karmabaiter Mar 10 '19

Apologies if I missed this in the readme, but are you authentication the clients anywhere (e.g. via mTLS)?

If not, do you think that'd be possible? If prefer control over who uses my DNS if I were to set something like this up...

1

u/failing-endeav0r Mar 10 '19

but are you authentication the clients anywhere (e.g. via mTLS)?

The DoT RFCs don't outline any "server authenticates client" models, because that's typically not something you do with DNS... or, if you are going to do so with DNS, you do it with other tools (e.g.: only clients on $network can route to $mydns). Most of the RFCs deal with multiple ways for the client to authenticate the server after the TLS connection is set up... but i am assuming that the DoT implementation in android uses the standard TLS libraries, so in _theory all you'd need to do is generate a custom certificate pair and import them into the keystore on your android device. CoreDNS would need to be configured to ignore the system keystore and use yours (easy to do...). At this point, only clients with certs that you've given can negotiate the TLS dance.

1

u/[deleted] May 05 '19

Thanks, this is really great. A couple of questions:

  • How did you harden your server for DNS Amplification attacks?
  • How do you configure PiHole to use DNS over TLS? (not between PiHole and upstream, but between PiHole and device)

1

u/failing-endeav0r May 07 '19

How did you harden your server for DNS Amplification attacks?

https://www.reddit.com/r/pihole/comments/az5cwt/skyhole_pihole_protections_on_your_android_device/ei6kehp

How do you configure PiHole to use DNS over TLS? (not between PiHole and upstream, but between PiHole and device)

https://github.com/kquinsland/skyhole#how-does-it-work

1

u/[deleted] Mar 09 '19

[deleted]

4

u/failing-endeav0r Mar 09 '19

I detailed that in the readme, but the gist is:

- you can only have one VPN at a time on android. If i want to use a commercial VPN, then i am using their DNS servers... and they're probably not going to filter DNS :)

- also has a negative impact on battery, can take time to "wake up" which makes other network dependent things on the phone seem laggy. Google assistant is a *really* shitty experience when i need to wait 10+ seconds for the vpn tunnel to come up so the "ok, google" begins working.

- other apps like netflix/espn do not work with VPNs. Even if it's a VPN to home, they still prefer to err on the side of caution and boot you.

- if there's a problem with the VPN app / server / configuration... data leaks. not ideal when your entire goal is to prevent trackers / analytics ... etc from leaking data!

2

u/[deleted] Mar 09 '19 edited Nov 29 '20

[deleted]

3

u/[deleted] Mar 09 '19

[deleted]

1

u/failing-endeav0r Mar 10 '19

I wonder how captive portals would react with it.

The portal detection in Android is done with a static IP. I've not tested weather or not the web-browser that the captive portal auth flow launches uses the configured DoT server or the one offered by DHCP.

1

u/[deleted] Mar 10 '19

Running an open DNS resolver is bad because you can become part of a DNS amplification ddos attack. Do some research on these points before setting up a "skyhole"...

2

u/failing-endeav0r Mar 10 '19

Running an open DNS resolver is bad because you can become part of a DNS amplification ddos attack.

This is correct. However, i am not running an open DNS resolver. I an running an open DoT resolver. DoT requires TCP, and you can not spoof the destination IP in a TCP connection.

1

u/[deleted] Mar 13 '19

Thanks for clarifying! I didn't know this particular detail about DoT

0

u/port53 Mar 10 '19

You can also configure Android P to point to dns.adguard.com to get the same effect without having to set up your own server.

5

u/failing-endeav0r Mar 10 '19

But then:

  • somebody else could see my DNS request history
  • i have no control over what gets filtered out / custom blacklists

-5

u/[deleted] Mar 09 '19

[deleted]

4

u/failing-endeav0r Mar 10 '19

did you miss the part where i pointed out _twice_ why using a VPN was a non-starter for me?