Gentoo Archives: gentoo-user

From: Peter Humphrey <peter@××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Setting a fixed nameserver for openvpn
Date: Mon, 06 Mar 2023 11:08:19
Message-Id: 2292476.ElGaqSPkdT@wstn
In Reply to: Re: [gentoo-user] Setting a fixed nameserver for openvpn by Wols Lists
1 On Monday, 6 March 2023 10:56:37 GMT Wols Lists wrote:
2 > On 06/03/2023 10:06, Michael wrote:
3
4 > > I suspect the behaviour you noticed is related to FF functionality like
5 > > TRR
6 > > (Trusted Recursive Resolver) farming all your DNS queries over to the
7 > > cloudfarce honeypot.
8 > >
9 > > Have a look here if you want to disable it:
10 > >
11 > > https://wiki.archlinux.org/title/Firefox/Privacy#Disable/
12 > > enforce_'Trusted_Recursive_Resolver'
13 >
14 > Thanks. That led me to network.trr.allow-rfc1918, which provided your
15 > name has a dot in it ! appears to resolve addresses from /etc/hosts. I
16 > guess that actually means firefox uses your local resolver first, and if
17 > it returns an rfc1918 address, will use it.
18 >
19 > Surely that should be the default! It shouldn't break a PRIVATE network
20 > in the name of security !!!
21
22 It is the default here, in www-client/firefox-110.0.1 .
23
24 --
25 Regards,
26 Peter.

Replies

Subject Author
Re: [gentoo-user] Setting a fixed nameserver for openvpn Wols Lists <antlists@××××××××××××.uk>