Path: csiph.com!v102.xanadu-bbs.net!xanadu-bbs.net!feeder.erje.net!us.feeder.erje.net!newsfeed.fsmpi.rwth-aachen.de!newsfeed.straub-nv.de!news-1.dfn.de!news.dfn.de!news1.uni-leipzig.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Tim Watts Newsgroups: uk.d-i-y,uk.comp.os.linux,comp.os.linux.misc Subject: Re: Parental guardian - internet (WEB) filtering Date: Thu, 02 Apr 2015 01:10:55 +0100 Lines: 63 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-Trace: individual.net NTG6Xe8JRD1fEnfgHLucywTwoypvBgN7BvFPzlT3bHMNluq0ln X-Orig-Path: squidward.dionic.net!not-for-mail Cancel-Lock: sha1:khOBc4z8yZQgyV5aMKS1JrqCgyg= User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0 In-Reply-To: Xref: csiph.com comp.os.linux.misc:14307 On 01/04/15 23:50, John Rumm wrote: > On 31/03/2015 18:36, Tim Watts wrote: > >> Please, no debates about the merits of this - >> >> I'm having trouble trying to find anything that might work. >> >> >> DNS based: >> ========== >> OpenDNS https://www.opendns.com/home-internet-security/ >> is going to be tricky trying to make that work alongside Unblock-US >> which is also DNS based. I might be able to track down the relevant >> Netflix zones and declared them in my local DNS server and refer those >> to UnblockUS whilst the default is to OpenDNS. In many ways though this >> is the easiest solution, except that it has to work along side UnblockUS. >> >> No worries about the kids setting their own DNS servers, I'll deal with >> that in the firewall :) > > Sticking cache: in front of the google search usually does for many DNS > blocks ;-) Indeed - I just discovered a nasty in that google image search embed the porn^H^H^H^Hresults as data URIs in the HTML. So OpenDNS cannot block them. But there's a little known feature in Google in that if you set your DNS to resolve www.google.* to the CNAME forcesafesearch.google.com then that does what it says - clever... As for cache - good point. I think you cannot get everything - but reducing the volume and ease is OK - mostly at this stage I want to remove the "by accident" factor... >> Proxy >> ===== >> eg Squidguard - It will not work with SSL traffic. Well, it might, but >> then all my browsers will throw up man-in-the-middle warnings. Seems >> like a non starter. >> >> Bloody big blacklist of IPs >> =========================== >> Assuming I can load several million into iptables without blowing up the >> router (see below), this could work. >> >> >> Any approaches I've missed? Does not need to be perfect - just good >> enough to mostly keep them off rotten.com, jihadist beheading vids and >> hard core porn. And if they hack their way around it, good for them - at >> least they are working for it - no illusions that they will be defeated >> for ever. > > If you still have the Draytek 2830, you can install (paid for extra) a > filter in the router itself - that cuts off most of the available > circumventions. I did try that - and it looked interesting, but I've now dropped the Vigor in favour of a linux router as it was too buggy and alien to work with.