Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #14284 > unrolled thread
| Started by | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| First post | 2015-03-31 18:36 +0100 |
| Last post | 2015-04-09 13:35 +0100 |
| Articles | 20 on this page of 38 — 14 participants |
Back to article view | Back to comp.os.linux.misc
Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 18:36 +0100
Re: Parental guardian - internet (WEB) filtering Andy Cap <snruwfpgbizo@trashmail.net> - 2015-03-31 18:44 +0100
Re: Parental guardian - internet (WEB) filtering "Dave Liquorice" <allsortsnotthisbit@howhill.com> - 2015-03-31 19:25 +0000
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 22:13 +0100
Re: Parental guardian - internet (WEB) filtering "Dave Liquorice" <allsortsnotthisbit@howhill.com> - 2015-04-02 00:03 +0000
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-02 01:14 +0100
Re: Parental guardian - internet (WEB) filtering Bill <Billaboard@gmail.com> - 2015-03-31 20:14 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 22:07 +0100
Re: Parental guardian - internet (WEB) filtering Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2015-03-31 15:18 -0700
Re: Parental guardian - internet (WEB) filtering The Real Doctor <ian.groups@btinternet.com> - 2015-04-01 23:10 +0100
Re: Parental guardian - internet (WEB) filtering Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2015-04-01 17:01 -0700
Re: Parental guardian - internet (WEB) filtering "Rod Speed" <rod.speed.aaa@gmail.com> - 2015-04-02 11:38 +1100
Re: Parental guardian - internet (WEB) filtering "john james" <jj9801@nospam.com> - 2015-04-01 06:59 +1100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 22:13 +0100
Re: Parental guardian - internet (WEB) filtering Capitol <spam@wher.eva.co.uk> - 2015-03-31 22:19 +0100
Re: Parental guardian - internet (WEB) filtering "john james" <jj9801@nospam.com> - 2015-04-01 09:46 +1100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-01 00:19 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-01 16:30 +0100
Re: Parental guardian - internet (WEB) filtering John Rumm <see.my.signature@nowhere.null> - 2015-04-01 23:50 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-02 01:10 +0100
Re: Parental guardian - internet (WEB) filtering Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2015-04-03 17:52 -0700
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 09:09 +0100
Re: Parental guardian - internet (WEB) filtering Martin Gregorie <martin@address-in-sig.invalid> - 2015-04-04 12:24 +0000
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 19:25 +0100
Re: Parental guardian - internet (WEB) filtering Martin Gregorie <martin@address-in-sig.invalid> - 2015-04-04 19:29 +0000
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 20:53 +0100
Re: Parental guardian - internet (WEB) filtering Martin Gregorie <martin@address-in-sig.invalid> - 2015-04-04 21:58 +0000
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 23:18 +0100
Re: Parental guardian - internet (WEB) filtering Richard Kettlewell <rjk@greenend.org.uk> - 2015-04-04 21:28 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 21:37 +0100
Re: Parental guardian - internet (WEB) filtering Andy Burns <usenet.feb2014@adslpipe.co.uk> - 2015-04-05 02:50 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-05 10:58 +0100
Re: Parental guardian - internet (WEB) filtering Andy Burns <usenet.feb2014@adslpipe.co.uk> - 2015-04-05 11:27 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 13:57 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 19:35 +0100
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 21:39 +0100
Re: Parental guardian - internet (WEB) filtering usenet@cucumber.me.uk (Andrew Gabriel) - 2015-04-09 09:29 +0000
Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-09 13:35 +0100
Page 1 of 2 [1] 2 Next page →
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-03-31 18:36 +0100 |
| Subject | Parental guardian - internet (WEB) filtering |
| Message-ID | <vh2rub-54e.ln1@squidward.dionic.net> |
Please, no debates about the merits of this - I'm having trouble trying to find anything that might work. DNS based: ========== OpenDNS https://www.opendns.com/home-internet-security/ is going to be tricky trying to make that work alongside Unblock-US which is also DNS based. I might be able to track down the relevant Netflix zones and declared them in my local DNS server and refer those to UnblockUS whilst the default is to OpenDNS. In many ways though this is the easiest solution, except that it has to work along side UnblockUS. No worries about the kids setting their own DNS servers, I'll deal with that in the firewall :) Proxy ===== eg Squidguard - It will not work with SSL traffic. Well, it might, but then all my browsers will throw up man-in-the-middle warnings. Seems like a non starter. Bloody big blacklist of IPs =========================== Assuming I can load several million into iptables without blowing up the router (see below), this could work. Any approaches I've missed? Does not need to be perfect - just good enough to mostly keep them off rotten.com, jihadist beheading vids and hard core porn. And if they hack their way around it, good for them - at least they are working for it - no illusions that they will be defeated for ever. Cheers Tim Equipment I have: Nice linux router running Debian 7 (this is are full blown nano system with lots of RAM, not embedded). It is my PPPoE endpoint, firewall, router, DNS, DHCP NAT and kerberos box. So I'd like to put 2 of my VLANs onto a filtered feed whilst leaving the main VLANs unfiltered. My VLANs are like this: 1) Public IP /27 block 2) Private "Golden" 10.0.0.0/24 block 3) Media 10.0.1.0/24 block for Netflix etc - Chromecast, Roku and phones/pads will use this 4) Guest net 10.0.2.0/24 Each maps to a separate WIFI ESSID. 1+2 unfiltered 3+4 filtered all the time. Only difference between 3 and 4 is 4 can get a new password every few weeks, without having to change Chromecast, Roku and other stuff. Assume the kids do not ever get to access 1+2.
[toc] | [next] | [standalone]
| From | Andy Cap <snruwfpgbizo@trashmail.net> |
|---|---|
| Date | 2015-03-31 18:44 +0100 |
| Message-ID | <mbWdnQAh0KF_QYfInZ2dnUVZ7o2dnZ2d@brightview.co.uk> |
| In reply to | #14284 |
On 31/03/15 18:36, Tim Watts wrote: > Please, no debates about the merits of this - > > I'm having trouble trying to find anything that might work. > > > DNS based: > ========== > OpenDNS https://www.opendns.com/home-internet-security/ > is going to be tricky trying to make that work alongside Unblock-US > which is also DNS based. I might be able to track down the relevant > Netflix zones and declared them in my local DNS server and refer those > to UnblockUS whilst the default is to OpenDNS. In many ways though this > is the easiest solution, except that it has to work along side UnblockUS. > > No worries about the kids setting their own DNS servers, I'll deal with > that in the firewall :) > > > > Proxy > ===== > eg Squidguard - It will not work with SSL traffic. Well, it might, but > then all my browsers will throw up man-in-the-middle warnings. Seems > like a non starter. > > Bloody big blacklist of IPs > =========================== > Assuming I can load several million into iptables without blowing up the > router (see below), this could work. > > > Any approaches I've missed? Does not need to be perfect - just good > enough to mostly keep them off rotten.com, jihadist beheading vids and > hard core porn. And if they hack their way around it, good for them - at > least they are working for it - no illusions that they will be defeated > for ever. > > > Cheers > > Tim > > > > Equipment I have: > > Nice linux router running Debian 7 (this is are full blown nano system > with lots of RAM, not embedded). It is my PPPoE endpoint, firewall, > router, DNS, DHCP NAT and kerberos box. > > > So I'd like to put 2 of my VLANs onto a filtered feed whilst leaving the > main VLANs unfiltered. My VLANs are like this: > > 1) Public IP /27 block > 2) Private "Golden" 10.0.0.0/24 block > 3) Media 10.0.1.0/24 block for Netflix etc - Chromecast, Roku and > phones/pads will use this > 4) Guest net 10.0.2.0/24 > > Each maps to a separate WIFI ESSID. > > 1+2 unfiltered > 3+4 filtered all the time. > > Only difference between 3 and 4 is 4 can get a new password every few > weeks, without having to change Chromecast, Roku and other stuff. > > Assume the kids do not ever get to access 1+2. Wont they just go round to their mate's house ?
[toc] | [prev] | [next] | [standalone]
| From | "Dave Liquorice" <allsortsnotthisbit@howhill.com> |
|---|---|
| Date | 2015-03-31 19:25 +0000 |
| Message-ID | <nyyfbegfubjuvyypbz.nm3qja0.pminews@srv1.howhill.co.uk> |
| In reply to | #14284 |
On Tue, 31 Mar 2015 18:36:31 +0100, Tim Watts wrote: > Please, no debates about the merits of this - > > I'm having trouble trying to find anything that might work. Never bothered with our two but the computer they used was in the breakfast room and anyone passing through could see what was on screen. We also took the time to try and make 'em Web Wise. As some one else has said stop 'em at home they'll just find it at a mates house... > Bloody big blacklist of IPs Surely you just do it with blocks and masks? -- Cheers Dave.
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-03-31 22:13 +0100 |
| Message-ID | <t8frub-kpi.ln1@squidward.dionic.net> |
| In reply to | #14288 |
On 31/03/15 20:25, Dave Liquorice wrote: > On Tue, 31 Mar 2015 18:36:31 +0100, Tim Watts wrote: > >> Please, no debates about the merits of this - >> >> I'm having trouble trying to find anything that might work. > > Never bothered with our two but the computer they used was in the > breakfast room and anyone passing through could see what was on > screen. We also took the time to try and make 'em Web Wise. As some > one else has said stop 'em at home they'll just find it at a mates > house... Thing is these days - there are phones and pads everywhere. I don;t care about someone's mates network - I care about mine. Back in the day, when you found your old man's stash of porn on top of the wardrobe (oh please.... at least try to hide it) it was just Playboy and the like. Now on the internet they're likely to find some bird with a donkey's knob in their <various orifices) and 3 dudes doing a rape porn job on someone. This is what we are trying to filter. In fact I might just leave some tasteful porn in the filter so they think they've got one over on me... >> Bloody big blacklist of IPs > > Surely you just do it with blocks and masks? > I wouldn't have thought it would be at the block level - I have not studied porn hosting in detail to work out if lots of porno outfits like a certain web host or ISP - maybe....
[toc] | [prev] | [next] | [standalone]
| From | "Dave Liquorice" <allsortsnotthisbit@howhill.com> |
|---|---|
| Date | 2015-04-02 00:03 +0000 |
| Message-ID | <nyyfbegfubjuvyypbz.nm5y255.pminews@srv1.howhill.co.uk> |
| In reply to | #14292 |
On Tue, 31 Mar 2015 22:13:33 +0100, Tim Watts wrote: >> Never bothered with our two but the computer they used was in the >> breakfast room and anyone passing through could see what was on >> screen. We also took the time to try and make 'em Web Wise. As some >> one else has said stop 'em at home they'll just find it at a mates >> house... > > Thing is these days - there are phones and pads everywhere. I don;t care > about someone's mates network - I care about mine. So is this about keeping your (as in you are legally responsible for) connection "clean" or about protecting the kids? The former you should fall into the "communication provider": http://aa.net.uk/legal-cp.html > Now on the internet they're likely to find some bird with a donkey's > knob in their <various orifices) and 3 dudes doing a rape porn job on > someone. Which may slip through your filters anyway so you still need to talk to the kids about what they might find out there. Being open upfront and frank may mean that if they do come across something that disturbs or upset them they might come and talk to you about it, rather than be worried about how you are going to react. > I wouldn't have thought it would be at the block level - I have not > studied porn hosting in detail to work out if lots of porno outfits like > a certain web host or ISP - maybe.... Porn is *BIG* business, I've not looked into it either but I wouldn't be at all surprised if they didn't have their own server farms, peering connections etc etc. -- Cheers Dave.
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-04-02 01:14 +0100 |
| Message-ID | <m8euub-ug9.ln1@squidward.dionic.net> |
| In reply to | #14304 |
On 02/04/15 01:03, Dave Liquorice wrote: > So is this about keeping your (as in you are legally responsible for) > connection "clean" or about protecting the kids? The former you > should fall into the "communication provider": > > http://aa.net.uk/legal-cp.html It's neither - it's about configuring my network the way I want it with respect to my kids. I cannot protect them from naughty pics in someone else's home anymor ethan I can protect them from falling under a bus. I however will not allow buses to be driven in my home. >> Now on the internet they're likely to find some bird with a donkey's >> knob in their <various orifices) and 3 dudes doing a rape porn job on >> someone. > > Which may slip through your filters anyway so you still need to talk > to the kids about what they might find out there. Being open upfront > and frank may mean that if they do come across something that > disturbs or upset them they might come and talk to you about it, > rather than be worried about how you are going to react. Yeah year - I agree with all that - but as mentioned in my last post, it's too easy to get an eye full just by mistyping a search term in google. And I certainly don't want them going onto rotten.com under any circumstances, ever! >> I wouldn't have thought it would be at the block level - I have not >> studied porn hosting in detail to work out if lots of porno outfits like >> a certain web host or ISP - maybe.... > > Porn is *BIG* business, I've not looked into it either but I wouldn't > be at all surprised if they didn't have their own server farms, > peering connections etc etc. >
[toc] | [prev] | [next] | [standalone]
| From | Bill <Billaboard@gmail.com> |
|---|---|
| Date | 2015-03-31 20:14 +0100 |
| Message-ID | <H9QrthC+HvGVFwNv@itsound.demon.co.uk> |
| In reply to | #14284 |
In message <vh2rub-54e.ln1@squidward.dionic.net>, Tim Watts <tw_usenet@dionic.net> writes >Please, no debates about the merits of this - > >I'm having trouble trying to find anything that might work. It might be worth mentioning that my brother-in-law had something installed on his Windows PC. It was about 3 years ago, his first machine and his first experience of computers and the internet, so he wanted to keep visiting family safe. His granddaughter visited, accessed it and managed to lock him out. When he discovered this, she was back at her home, and claimed innocence, no knowledge of password etc. I think he ended up having to have the machine rebuilt from scratch. -- Bill
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-03-31 22:07 +0100 |
| Message-ID | <fuerub-gci.ln1@squidward.dionic.net> |
| In reply to | #14289 |
On 31/03/15 20:14, Bill wrote: > In message <vh2rub-54e.ln1@squidward.dionic.net>, Tim Watts > <tw_usenet@dionic.net> writes >> Please, no debates about the merits of this - >> >> I'm having trouble trying to find anything that might work. > > It might be worth mentioning that my brother-in-law had something > installed on his Windows PC. It was about 3 years ago, his first machine > and his first experience of computers and the internet, so he wanted to > keep visiting family safe. > > His granddaughter visited, accessed it and managed to lock him out. When > he discovered this, she was back at her home, and claimed innocence, no > knowledge of password etc. > > I think he ended up having to have the machine rebuilt from scratch. That's why we're doing it at the router :)
[toc] | [prev] | [next] | [standalone]
| From | Bobbie Sellers <bliss-sf4ever@dslextreme.com> |
|---|---|
| Date | 2015-03-31 15:18 -0700 |
| Message-ID | <mff6eh$ids$1@dont-email.me> |
| In reply to | #14289 |
On 03/31/2015 12:14 PM, Bill wrote: > In message <vh2rub-54e.ln1@squidward.dionic.net>, Tim Watts > <tw_usenet@dionic.net> writes >> Please, no debates about the merits of this - >> >> I'm having trouble trying to find anything that might work. > > It might be worth mentioning that my brother-in-law had something > installed on his Windows PC. It was about 3 years ago, his first machine > and his first experience of computers and the internet, so he wanted to > keep visiting family safe. > > His granddaughter visited, accessed it and managed to lock him out. When > he discovered this, she was back at her home, and claimed innocence, no > knowledge of password etc. > > I think he ended up having to have the machine rebuilt from scratch. That is pathetic as a password on a Windows machine could replaced or totally removed by use of Linux tool. Not so easily done since Windows 8 but still possible. You don't say which Linux distribution you are using but on the Mandriva derived Mageia, PCLOS and Open Mandriva there are plenty of places to control access. If you were to set up separate guest accounts for adults and for children you could easily manage this. Of course you have to have a place to lock up your Linux tools which could circumvent the limits on the accounts. bliss
[toc] | [prev] | [next] | [standalone]
| From | The Real Doctor <ian.groups@btinternet.com> |
|---|---|
| Date | 2015-04-01 23:10 +0100 |
| Message-ID | <mfhqaq$nb1$2@dont-email.me> |
| In reply to | #14295 |
On 31/03/15 23:18, Bobbie Sellers wrote: > That is pathetic as a password on a Windows machine could > replaced or totally removed by use of Linux tool. If she managed to set the BIOS password on a ThinkPad or ThinkCentre the only solution would be to solder in a new security chip. Those babies are tough. Ian
[toc] | [prev] | [next] | [standalone]
| From | Bobbie Sellers <bliss-sf4ever@dslextreme.com> |
|---|---|
| Date | 2015-04-01 17:01 -0700 |
| Message-ID | <mfi0r8$cdq$1@dont-email.me> |
| In reply to | #14302 |
On 04/01/2015 03:10 PM, The Real Doctor wrote: > On 31/03/15 23:18, Bobbie Sellers wrote: >> That is pathetic as a password on a Windows machine could >> replaced or totally removed by use of Linux tool. > > If she managed to set the BIOS password on a ThinkPad or ThinkCentre the > only solution would be to solder in a new security chip. Those babies > are tough. > > Ian Yes but there was no mention of BIOS password changes, to the time when I replied. Recovering from such a problem could be done by exchanging main boards where, I presume, the BIOS/(U)EFI lives. It could be prevented by setting a password on the BIOS before little "crackers" come to visit. bliss
[toc] | [prev] | [next] | [standalone]
| From | "Rod Speed" <rod.speed.aaa@gmail.com> |
|---|---|
| Date | 2015-04-02 11:38 +1100 |
| Message-ID | <co3hfeFpegU1@mid.individual.net> |
| In reply to | #14306 |
"Bobbie Sellers" <bliss-sf4ever@dslextreme.com> wrote in message news:mfi0r8$cdq$1@dont-email.me... > On 04/01/2015 03:10 PM, The Real Doctor wrote: >> On 31/03/15 23:18, Bobbie Sellers wrote: >>> That is pathetic as a password on a Windows machine could >>> replaced or totally removed by use of Linux tool. >> >> If she managed to set the BIOS password on a ThinkPad or ThinkCentre the >> only solution would be to solder in a new security chip. Those babies >> are tough. > Yes but there was no mention of BIOS password changes, to the time when I > replied. Recovering from such a problem could be done > by exchanging main boards Fraid not. > where, I presume, the BIOS/(U)EFI lives. > It could be prevented by setting a password on the BIOS > before little "crackers" come to visit.
[toc] | [prev] | [next] | [standalone]
| From | "john james" <jj9801@nospam.com> |
|---|---|
| Date | 2015-04-01 06:59 +1100 |
| Message-ID | <co0cntF6jo5U1@mid.individual.net> |
| In reply to | #14284 |
"Tim Watts" <tw_usenet@dionic.net> wrote in message news:vh2rub-54e.ln1@squidward.dionic.net... > Please, no debates about the merits of this - > > I'm having trouble trying to find anything that might work. > > > DNS based: > ========== > OpenDNS https://www.opendns.com/home-internet-security/ > is going to be tricky trying to make that work alongside Unblock-US which > is also DNS based. I might be able to track down the relevant Netflix > zones and declared them in my local DNS server and refer those to > UnblockUS whilst the default is to OpenDNS. In many ways though this is > the easiest solution, except that it has to work along side UnblockUS. > > No worries about the kids setting their own DNS servers, I'll deal with > that in the firewall :) > > > > Proxy > ===== > eg Squidguard - It will not work with SSL traffic. Well, it might, but > then all my browsers will throw up man-in-the-middle warnings. Seems like > a non starter. > > Bloody big blacklist of IPs > =========================== > Assuming I can load several million into iptables without blowing up the > router (see below), this could work. > > > Any approaches I've missed? Does not need to be perfect - just good enough > to mostly keep them off rotten.com, jihadist beheading vids and hard core > porn. And if they hack their way around it, good for them - at least they > are working for it - no illusions that they will be defeated for ever. > > > Cheers > > Tim > > > > Equipment I have: > > Nice linux router running Debian 7 (this is are full blown nano system > with lots of RAM, not embedded). It is my PPPoE endpoint, firewall, > router, DNS, DHCP NAT and kerberos box. > > > So I'd like to put 2 of my VLANs onto a filtered feed whilst leaving the > main VLANs unfiltered. My VLANs are like this: > > 1) Public IP /27 block > 2) Private "Golden" 10.0.0.0/24 block > 3) Media 10.0.1.0/24 block for Netflix etc - Chromecast, Roku and > phones/pads will use this > 4) Guest net 10.0.2.0/24 > > Each maps to a separate WIFI ESSID. > > 1+2 unfiltered > 3+4 filtered all the time. > > Only difference between 3 and 4 is 4 can get a new password every few > weeks, without having to change Chromecast, Roku and other stuff. > > Assume the kids do not ever get to access 1+2. Don’t forget who will be picking your nursing home.
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-03-31 22:13 +0100 |
| Message-ID | <n9frub-kpi.ln1@squidward.dionic.net> |
| In reply to | #14290 |
On 31/03/15 20:59, john james wrote: > > Don’t forget who will be picking your nursing home. I will...
[toc] | [prev] | [next] | [standalone]
| From | Capitol <spam@wher.eva.co.uk> |
|---|---|
| Date | 2015-03-31 22:19 +0100 |
| Message-ID | <1JCdnX_9Yd62kobInZ2dnUVZ7smdnZ2d@brightview.co.uk> |
| In reply to | #14293 |
Tim Watts wrote: > On 31/03/15 20:59, john james wrote: >> >> Don’t forget who will be picking your nursing home. > > I will... Wishful thinking?
[toc] | [prev] | [next] | [standalone]
| From | "john james" <jj9801@nospam.com> |
|---|---|
| Date | 2015-04-01 09:46 +1100 |
| Message-ID | <co0mgeF9467U1@mid.individual.net> |
| In reply to | #14293 |
"Tim Watts" <tw_usenet@dionic.net> wrote in message news:n9frub-kpi.ln1@squidward.dionic.net... > On 31/03/15 20:59, john james wrote: >> >> Don’t forget who will be picking your nursing home. > > I will... We'll see... My dad thought that. He didn’t.
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-04-01 00:19 +0100 |
| Message-ID | <almrub-dln.ln1@squidward.dionic.net> |
| In reply to | #14296 |
On 31/03/15 23:46, john james wrote:
>
>
> "Tim Watts" <tw_usenet@dionic.net> wrote in message
> news:n9frub-kpi.ln1@squidward.dionic.net...
>> On 31/03/15 20:59, john james wrote:
>>>
>>> Don’t forget who will be picking your nursing home.
>>
>> I will...
>
> We'll see...
>
> My dad thought that. He didn’t.
Hmm - the lack of "do it this way" responses suggests this needs a novel
solution.
Thanks folks - just checking I was not missing something obvious.
OK - I think the final solution will maybe look like:
My DNS ->
Split views, ie a different view based on client IP (I do this already,
nice feature of Bind9) -
VLAN 1+2 resolve normally.
VLAN 3+4 by default pass non local-authoritative queries to OpenDNS
subscription service for filtering.
But I try to define zones for netflix.com (and any supporting ones, not
sure it it uses akamai or similar, but a bit of tcpdum will tell me) -
these zones are defiend locally as forwarder zones aka:
zone "netflix.com" IN {
type forward;
forwarders {
<unblockus-DNS-servers>;
};
};
I think that might work -
Only one way - just have to try it.
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-04-01 16:30 +0100 |
| Message-ID | <rgftub-s28.ln1@squidward.dionic.net> |
| In reply to | #14297 |
On 01/04/15 00:19, Tim Watts wrote:
> zone "netflix.com" IN {
> type forward;
> forwarders {
> <unblockus-DNS-servers>;
> };
> };
>
>
> I think that might work -
>
> Only one way - just have to try it.
This is very informative:
http://digiex.net/guides-reviews/guides-tutorials/networking-guides/11876-using-unblock-us-without-switching-dns-server-watch-netflix-outside-us.html
It looks like I will only have to subvert domain lookups for netflix.com
and netflix.net.
Hmm - if the bind9 stanza above works, this could be very easy :)
[toc] | [prev] | [next] | [standalone]
| From | John Rumm <see.my.signature@nowhere.null> |
|---|---|
| Date | 2015-04-01 23:50 +0100 |
| Message-ID | <NKydnSdVs5uo64HInZ2dnUVZ8hqdnZ2d@brightview.co.uk> |
| In reply to | #14284 |
On 31/03/2015 18:36, Tim Watts wrote: > Please, no debates about the merits of this - > > I'm having trouble trying to find anything that might work. > > > DNS based: > ========== > OpenDNS https://www.opendns.com/home-internet-security/ > is going to be tricky trying to make that work alongside Unblock-US > which is also DNS based. I might be able to track down the relevant > Netflix zones and declared them in my local DNS server and refer those > to UnblockUS whilst the default is to OpenDNS. In many ways though this > is the easiest solution, except that it has to work along side UnblockUS. > > No worries about the kids setting their own DNS servers, I'll deal with > that in the firewall :) Sticking cache: in front of the google search usually does for many DNS blocks ;-) > Proxy > ===== > eg Squidguard - It will not work with SSL traffic. Well, it might, but > then all my browsers will throw up man-in-the-middle warnings. Seems > like a non starter. > > Bloody big blacklist of IPs > =========================== > Assuming I can load several million into iptables without blowing up the > router (see below), this could work. > > > Any approaches I've missed? Does not need to be perfect - just good > enough to mostly keep them off rotten.com, jihadist beheading vids and > hard core porn. And if they hack their way around it, good for them - at > least they are working for it - no illusions that they will be defeated > for ever. If you still have the Draytek 2830, you can install (paid for extra) a filter in the router itself - that cuts off most of the available circumventions. -- Cheers, John. /=================================================================\ | Internode Ltd - http://www.internode.co.uk | |-----------------------------------------------------------------| | John Rumm - john(at)internode(dot)co(dot)uk | \=================================================================/
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-04-02 01:10 +0100 |
| Message-ID | <f1euub-ra9.ln1@squidward.dionic.net> |
| In reply to | #14303 |
On 01/04/15 23:50, John Rumm wrote: > On 31/03/2015 18:36, Tim Watts wrote: > >> Please, no debates about the merits of this - >> >> I'm having trouble trying to find anything that might work. >> >> >> DNS based: >> ========== >> OpenDNS https://www.opendns.com/home-internet-security/ >> is going to be tricky trying to make that work alongside Unblock-US >> which is also DNS based. I might be able to track down the relevant >> Netflix zones and declared them in my local DNS server and refer those >> to UnblockUS whilst the default is to OpenDNS. In many ways though this >> is the easiest solution, except that it has to work along side UnblockUS. >> >> No worries about the kids setting their own DNS servers, I'll deal with >> that in the firewall :) > > Sticking cache: in front of the google search usually does for many DNS > blocks ;-) Indeed - I just discovered a nasty in that google image search embed the porn^H^H^H^Hresults as data URIs in the HTML. So OpenDNS cannot block them. But there's a little known feature in Google in that if you set your DNS to resolve www.google.* to the CNAME forcesafesearch.google.com then that does what it says - clever... As for cache - good point. I think you cannot get everything - but reducing the volume and ease is OK - mostly at this stage I want to remove the "by accident" factor... >> Proxy >> ===== >> eg Squidguard - It will not work with SSL traffic. Well, it might, but >> then all my browsers will throw up man-in-the-middle warnings. Seems >> like a non starter. >> >> Bloody big blacklist of IPs >> =========================== >> Assuming I can load several million into iptables without blowing up the >> router (see below), this could work. >> >> >> Any approaches I've missed? Does not need to be perfect - just good >> enough to mostly keep them off rotten.com, jihadist beheading vids and >> hard core porn. And if they hack their way around it, good for them - at >> least they are working for it - no illusions that they will be defeated >> for ever. > > If you still have the Draytek 2830, you can install (paid for extra) a > filter in the router itself - that cuts off most of the available > circumventions. I did try that - and it looked interesting, but I've now dropped the Vigor in favour of a linux router as it was too buggy and alien to work with.
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | comp.os.linux.misc
csiph-web