Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #14284 > unrolled thread

Parental guardian - internet (WEB) filtering

Started byTim Watts <tw_usenet@dionic.net>
First post2015-03-31 18:36 +0100
Last post2015-04-09 13:35 +0100
Articles 20 on this page of 38 — 14 participants

Back to article view | Back to comp.os.linux.misc


Contents

  Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 18:36 +0100
    Re: Parental guardian - internet (WEB) filtering Andy Cap <snruwfpgbizo@trashmail.net> - 2015-03-31 18:44 +0100
    Re: Parental guardian - internet (WEB) filtering "Dave Liquorice" <allsortsnotthisbit@howhill.com> - 2015-03-31 19:25 +0000
      Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 22:13 +0100
        Re: Parental guardian - internet (WEB) filtering "Dave Liquorice" <allsortsnotthisbit@howhill.com> - 2015-04-02 00:03 +0000
          Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-02 01:14 +0100
    Re: Parental guardian - internet (WEB) filtering Bill <Billaboard@gmail.com> - 2015-03-31 20:14 +0100
      Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 22:07 +0100
      Re: Parental guardian - internet (WEB) filtering Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2015-03-31 15:18 -0700
        Re: Parental guardian - internet (WEB) filtering The Real Doctor <ian.groups@btinternet.com> - 2015-04-01 23:10 +0100
          Re: Parental guardian - internet (WEB) filtering Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2015-04-01 17:01 -0700
            Re: Parental guardian - internet (WEB) filtering "Rod Speed" <rod.speed.aaa@gmail.com> - 2015-04-02 11:38 +1100
    Re: Parental guardian - internet (WEB) filtering "john james" <jj9801@nospam.com> - 2015-04-01 06:59 +1100
      Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-03-31 22:13 +0100
        Re: Parental guardian - internet (WEB) filtering Capitol <spam@wher.eva.co.uk> - 2015-03-31 22:19 +0100
        Re: Parental guardian - internet (WEB) filtering "john james" <jj9801@nospam.com> - 2015-04-01 09:46 +1100
          Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-01 00:19 +0100
            Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-01 16:30 +0100
    Re: Parental guardian - internet (WEB) filtering John Rumm <see.my.signature@nowhere.null> - 2015-04-01 23:50 +0100
      Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-02 01:10 +0100
        Re: Parental guardian - internet (WEB) filtering Bobbie Sellers <bliss-sf4ever@dslextreme.com> - 2015-04-03 17:52 -0700
          Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 09:09 +0100
            Re: Parental guardian - internet (WEB) filtering Martin Gregorie <martin@address-in-sig.invalid> - 2015-04-04 12:24 +0000
              Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 19:25 +0100
                Re: Parental guardian - internet (WEB) filtering Martin Gregorie <martin@address-in-sig.invalid> - 2015-04-04 19:29 +0000
                  Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 20:53 +0100
                    Re: Parental guardian - internet (WEB) filtering Martin Gregorie <martin@address-in-sig.invalid> - 2015-04-04 21:58 +0000
                      Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 23:18 +0100
                Re: Parental guardian - internet (WEB) filtering Richard Kettlewell <rjk@greenend.org.uk> - 2015-04-04 21:28 +0100
                  Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 21:37 +0100
                Re: Parental guardian - internet (WEB) filtering Andy Burns <usenet.feb2014@adslpipe.co.uk> - 2015-04-05 02:50 +0100
                  Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-05 10:58 +0100
                    Re: Parental guardian - internet (WEB) filtering Andy Burns <usenet.feb2014@adslpipe.co.uk> - 2015-04-05 11:27 +0100
        Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 13:57 +0100
          Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 19:35 +0100
            Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-04 21:39 +0100
    Re: Parental guardian - internet (WEB) filtering usenet@cucumber.me.uk (Andrew Gabriel) - 2015-04-09 09:29 +0000
      Re: Parental guardian - internet (WEB) filtering Tim Watts <tw_usenet@dionic.net> - 2015-04-09 13:35 +0100

Page 1 of 2  [1] 2  Next page →


#14284 — Parental guardian - internet (WEB) filtering

FromTim Watts <tw_usenet@dionic.net>
Date2015-03-31 18:36 +0100
SubjectParental guardian - internet (WEB) filtering
Message-ID<vh2rub-54e.ln1@squidward.dionic.net>
Please, no debates about the merits of this -

I'm having trouble trying to find anything that might work.


DNS based:
==========
OpenDNS https://www.opendns.com/home-internet-security/
is going to be tricky trying to make that work alongside Unblock-US 
which is also DNS based. I might be able to track down the relevant 
Netflix zones and declared them in my local DNS server and refer those 
to UnblockUS whilst the default is to OpenDNS. In many ways though this 
is the easiest solution, except that it has to work along side UnblockUS.

No worries about the kids setting their own DNS servers, I'll deal with 
that in the firewall :)



Proxy
=====
eg Squidguard - It will not work with SSL traffic. Well, it might, but 
then all my browsers will throw up man-in-the-middle warnings. Seems 
like a non starter.

Bloody big blacklist of IPs
===========================
Assuming I can load several million into iptables without blowing up the 
router (see below), this could work.


Any approaches I've missed? Does not need to be perfect - just good 
enough to mostly keep them off rotten.com, jihadist beheading vids and 
hard core porn. And if they hack their way around it, good for them - at 
least they are working for it - no illusions that they will be defeated 
for ever.


Cheers

Tim



Equipment I have:

Nice linux router running Debian 7 (this is are full blown nano system 
with lots of RAM, not embedded). It is my PPPoE endpoint, firewall, 
router, DNS, DHCP NAT and kerberos box.


So I'd like to put 2 of my VLANs onto a filtered feed whilst leaving the 
main VLANs unfiltered. My VLANs are like this:

1) Public IP /27 block
2) Private "Golden" 10.0.0.0/24 block
3) Media 10.0.1.0/24 block for Netflix etc - Chromecast, Roku and 
phones/pads will use this
4) Guest net 10.0.2.0/24

Each maps to a separate WIFI ESSID.

1+2 unfiltered
3+4 filtered all the time.

Only difference between 3 and 4 is 4 can get a new password every few 
weeks, without having to change Chromecast, Roku and other stuff.

Assume the kids do not ever get to access 1+2.

[toc] | [next] | [standalone]


#14285

FromAndy Cap <snruwfpgbizo@trashmail.net>
Date2015-03-31 18:44 +0100
Message-ID<mbWdnQAh0KF_QYfInZ2dnUVZ7o2dnZ2d@brightview.co.uk>
In reply to#14284
On 31/03/15 18:36, Tim Watts wrote:
> Please, no debates about the merits of this -
>
> I'm having trouble trying to find anything that might work.
>
>
> DNS based:
> ==========
> OpenDNS https://www.opendns.com/home-internet-security/
> is going to be tricky trying to make that work alongside Unblock-US
> which is also DNS based. I might be able to track down the relevant
> Netflix zones and declared them in my local DNS server and refer those
> to UnblockUS whilst the default is to OpenDNS. In many ways though this
> is the easiest solution, except that it has to work along side UnblockUS.
>
> No worries about the kids setting their own DNS servers, I'll deal with
> that in the firewall :)
>
>
>
> Proxy
> =====
> eg Squidguard - It will not work with SSL traffic. Well, it might, but
> then all my browsers will throw up man-in-the-middle warnings. Seems
> like a non starter.
>
> Bloody big blacklist of IPs
> ===========================
> Assuming I can load several million into iptables without blowing up the
> router (see below), this could work.
>
>
> Any approaches I've missed? Does not need to be perfect - just good
> enough to mostly keep them off rotten.com, jihadist beheading vids and
> hard core porn. And if they hack their way around it, good for them - at
> least they are working for it - no illusions that they will be defeated
> for ever.
>
>
> Cheers
>
> Tim
>
>
>
> Equipment I have:
>
> Nice linux router running Debian 7 (this is are full blown nano system
> with lots of RAM, not embedded). It is my PPPoE endpoint, firewall,
> router, DNS, DHCP NAT and kerberos box.
>
>
> So I'd like to put 2 of my VLANs onto a filtered feed whilst leaving the
> main VLANs unfiltered. My VLANs are like this:
>
> 1) Public IP /27 block
> 2) Private "Golden" 10.0.0.0/24 block
> 3) Media 10.0.1.0/24 block for Netflix etc - Chromecast, Roku and
> phones/pads will use this
> 4) Guest net 10.0.2.0/24
>
> Each maps to a separate WIFI ESSID.
>
> 1+2 unfiltered
> 3+4 filtered all the time.
>
> Only difference between 3 and 4 is 4 can get a new password every few
> weeks, without having to change Chromecast, Roku and other stuff.
>
> Assume the kids do not ever get to access 1+2.

Wont they just go round to their mate's house ?

[toc] | [prev] | [next] | [standalone]


#14288

From"Dave Liquorice" <allsortsnotthisbit@howhill.com>
Date2015-03-31 19:25 +0000
Message-ID<nyyfbegfubjuvyypbz.nm3qja0.pminews@srv1.howhill.co.uk>
In reply to#14284
On Tue, 31 Mar 2015 18:36:31 +0100, Tim Watts wrote:

> Please, no debates about the merits of this -
> 
> I'm having trouble trying to find anything that might work.

Never bothered with our two but the computer they used was in the
breakfast room and anyone passing through could see what was on
screen. We also took the time to try and make 'em Web Wise. As some
one else has said stop 'em at home they'll just find it at a mates
house...

> Bloody big blacklist of IPs

Surely you just do it with blocks and masks?

-- 
Cheers
Dave.


[toc] | [prev] | [next] | [standalone]


#14292

FromTim Watts <tw_usenet@dionic.net>
Date2015-03-31 22:13 +0100
Message-ID<t8frub-kpi.ln1@squidward.dionic.net>
In reply to#14288
On 31/03/15 20:25, Dave Liquorice wrote:
> On Tue, 31 Mar 2015 18:36:31 +0100, Tim Watts wrote:
>
>> Please, no debates about the merits of this -
>>
>> I'm having trouble trying to find anything that might work.
>
> Never bothered with our two but the computer they used was in the
> breakfast room and anyone passing through could see what was on
> screen. We also took the time to try and make 'em Web Wise. As some
> one else has said stop 'em at home they'll just find it at a mates
> house...

Thing is these days - there are phones and pads everywhere. I don;t care 
about someone's mates network - I care about mine.

Back in the day, when you found your old man's stash of porn on top of 
the wardrobe (oh please.... at least try to hide it) it was just Playboy 
and the like.

Now on the internet they're likely to find some bird with a donkey's 
knob in their <various orifices) and 3 dudes doing a rape porn job on 
someone.

This is what we are trying to filter. In fact I might just leave some 
tasteful porn in the filter so they think they've got one over on me...

>> Bloody big blacklist of IPs
>
> Surely you just do it with blocks and masks?
>

I wouldn't have thought it would be at the block level - I have not 
studied porn hosting in detail to work out if lots of porno outfits like 
a certain web host or ISP - maybe....

[toc] | [prev] | [next] | [standalone]


#14304

From"Dave Liquorice" <allsortsnotthisbit@howhill.com>
Date2015-04-02 00:03 +0000
Message-ID<nyyfbegfubjuvyypbz.nm5y255.pminews@srv1.howhill.co.uk>
In reply to#14292
On Tue, 31 Mar 2015 22:13:33 +0100, Tim Watts wrote:

>> Never bothered with our two but the computer they used was in the
>> breakfast room and anyone passing through could see what was on
>> screen. We also took the time to try and make 'em Web Wise. As
some
>> one else has said stop 'em at home they'll just find it at a mates
>> house...
> 
> Thing is these days - there are phones and pads everywhere. I don;t care 
> about someone's mates network - I care about mine.

So is this about keeping your (as in you are legally responsible for)
connection "clean" or about protecting the kids? The former you
should fall into the "communication provider":

http://aa.net.uk/legal-cp.html

> Now on the internet they're likely to find some bird with a donkey's 
> knob in their <various orifices) and 3 dudes doing a rape porn job on 
> someone.

Which may slip through your filters anyway so you still need to talk
to the kids about what they might find out there. Being open upfront
and frank may mean that if they do come across something that
disturbs or upset them they might come and talk to you about it,
rather than be worried about how you are going to react.

> I wouldn't have thought it would be at the block level - I have not 
> studied porn hosting in detail to work out if lots of porno outfits like 
> a certain web host or ISP - maybe....

Porn is *BIG* business, I've not looked into it either but I wouldn't
be at all surprised if they didn't have their own server farms,
peering connections etc etc.

-- 
Cheers
Dave.


[toc] | [prev] | [next] | [standalone]


#14308

FromTim Watts <tw_usenet@dionic.net>
Date2015-04-02 01:14 +0100
Message-ID<m8euub-ug9.ln1@squidward.dionic.net>
In reply to#14304
On 02/04/15 01:03, Dave Liquorice wrote:

> So is this about keeping your (as in you are legally responsible for)
> connection "clean" or about protecting the kids? The former you
> should fall into the "communication provider":
>
> http://aa.net.uk/legal-cp.html

It's neither - it's about configuring my network the way I want it with 
respect to my kids. I cannot protect them from naughty pics in someone 
else's home anymor ethan I can protect them from falling under a bus. I 
however will not allow buses to be driven in my home.

>> Now on the internet they're likely to find some bird with a donkey's
>> knob in their <various orifices) and 3 dudes doing a rape porn job on
>> someone.
>
> Which may slip through your filters anyway so you still need to talk
> to the kids about what they might find out there. Being open upfront
> and frank may mean that if they do come across something that
> disturbs or upset them they might come and talk to you about it,
> rather than be worried about how you are going to react.


Yeah year - I agree with all that - but as mentioned in my last post, 
it's too easy to get an eye full just by mistyping a search term in google.

And I certainly don't want them going onto rotten.com under any 
circumstances, ever!

>> I wouldn't have thought it would be at the block level - I have not
>> studied porn hosting in detail to work out if lots of porno outfits like
>> a certain web host or ISP - maybe....
>
> Porn is *BIG* business, I've not looked into it either but I wouldn't
> be at all surprised if they didn't have their own server farms,
> peering connections etc etc.
>

[toc] | [prev] | [next] | [standalone]


#14289

FromBill <Billaboard@gmail.com>
Date2015-03-31 20:14 +0100
Message-ID<H9QrthC+HvGVFwNv@itsound.demon.co.uk>
In reply to#14284
In message <vh2rub-54e.ln1@squidward.dionic.net>, Tim Watts 
<tw_usenet@dionic.net> writes
>Please, no debates about the merits of this -
>
>I'm having trouble trying to find anything that might work.

It might be worth mentioning that my brother-in-law had something 
installed on his Windows PC. It was about 3 years ago, his first machine 
and his first experience of computers and the internet, so he wanted to 
keep visiting family safe.

His granddaughter visited, accessed it and managed to lock him out. When 
he discovered this, she was back at her home, and claimed innocence, no 
knowledge of password etc.

I think he ended up having to have the machine rebuilt from scratch.
-- 
Bill

[toc] | [prev] | [next] | [standalone]


#14291

FromTim Watts <tw_usenet@dionic.net>
Date2015-03-31 22:07 +0100
Message-ID<fuerub-gci.ln1@squidward.dionic.net>
In reply to#14289
On 31/03/15 20:14, Bill wrote:
> In message <vh2rub-54e.ln1@squidward.dionic.net>, Tim Watts
> <tw_usenet@dionic.net> writes
>> Please, no debates about the merits of this -
>>
>> I'm having trouble trying to find anything that might work.
>
> It might be worth mentioning that my brother-in-law had something
> installed on his Windows PC. It was about 3 years ago, his first machine
> and his first experience of computers and the internet, so he wanted to
> keep visiting family safe.
>
> His granddaughter visited, accessed it and managed to lock him out. When
> he discovered this, she was back at her home, and claimed innocence, no
> knowledge of password etc.
>
> I think he ended up having to have the machine rebuilt from scratch.

That's why we're doing it at the router :)

[toc] | [prev] | [next] | [standalone]


#14295

FromBobbie Sellers <bliss-sf4ever@dslextreme.com>
Date2015-03-31 15:18 -0700
Message-ID<mff6eh$ids$1@dont-email.me>
In reply to#14289
On 03/31/2015 12:14 PM, Bill wrote:
> In message <vh2rub-54e.ln1@squidward.dionic.net>, Tim Watts
> <tw_usenet@dionic.net> writes
>> Please, no debates about the merits of this -
>>
>> I'm having trouble trying to find anything that might work.
>
> It might be worth mentioning that my brother-in-law had something
> installed on his Windows PC. It was about 3 years ago, his first machine
> and his first experience of computers and the internet, so he wanted to
> keep visiting family safe.
>
> His granddaughter visited, accessed it and managed to lock him out. When
> he discovered this, she was back at her home, and claimed innocence, no
> knowledge of password etc.
>
> I think he ended up having to have the machine rebuilt from scratch.

	That is pathetic as a password on a Windows machine could
replaced or totally removed by use of Linux tool.

	Not so easily done since Windows 8 but still possible.
	You don't say which Linux distribution you are using but
on the Mandriva derived Mageia, PCLOS and Open Mandriva there are
plenty of places to control access.  If you were to set up separate
guest accounts for adults and for children you could easily
manage this.
	Of course you have to have a place to lock up your Linux
tools which could circumvent the limits on the accounts.

	bliss

[toc] | [prev] | [next] | [standalone]


#14302

FromThe Real Doctor <ian.groups@btinternet.com>
Date2015-04-01 23:10 +0100
Message-ID<mfhqaq$nb1$2@dont-email.me>
In reply to#14295
On 31/03/15 23:18, Bobbie Sellers wrote:
> That is pathetic as a password on a Windows machine could
> replaced or totally removed by use of Linux tool.

If she managed to set the BIOS password on a ThinkPad or ThinkCentre the 
only solution would be to solder in a new security chip. Those babies 
are tough.

Ian

[toc] | [prev] | [next] | [standalone]


#14306

FromBobbie Sellers <bliss-sf4ever@dslextreme.com>
Date2015-04-01 17:01 -0700
Message-ID<mfi0r8$cdq$1@dont-email.me>
In reply to#14302
On 04/01/2015 03:10 PM, The Real Doctor wrote:
> On 31/03/15 23:18, Bobbie Sellers wrote:
>> That is pathetic as a password on a Windows machine could
>> replaced or totally removed by use of Linux tool.
>
> If she managed to set the BIOS password on a ThinkPad or ThinkCentre the
> only solution would be to solder in a new security chip. Those babies
> are tough.
>
> Ian

	Yes but there was no mention of BIOS password changes, to the time when 
I replied.  Recovering from such a problem could be done
by exchanging main boards where, I presume, the BIOS/(U)EFI lives.
	It could be prevented by setting a password on the BIOS
before little "crackers" come to visit.

	bliss

[toc] | [prev] | [next] | [standalone]


#14310

From"Rod Speed" <rod.speed.aaa@gmail.com>
Date2015-04-02 11:38 +1100
Message-ID<co3hfeFpegU1@mid.individual.net>
In reply to#14306

"Bobbie Sellers" <bliss-sf4ever@dslextreme.com> wrote in message 
news:mfi0r8$cdq$1@dont-email.me...
> On 04/01/2015 03:10 PM, The Real Doctor wrote:
>> On 31/03/15 23:18, Bobbie Sellers wrote:
>>> That is pathetic as a password on a Windows machine could
>>> replaced or totally removed by use of Linux tool.
>>
>> If she managed to set the BIOS password on a ThinkPad or ThinkCentre the
>> only solution would be to solder in a new security chip. Those babies
>> are tough.

> Yes but there was no mention of BIOS password changes, to the time when I 
> replied.  Recovering from such a problem could be done
> by exchanging main boards

Fraid not.

> where, I presume, the BIOS/(U)EFI lives.
> It could be prevented by setting a password on the BIOS
> before little "crackers" come to visit.
 

[toc] | [prev] | [next] | [standalone]


#14290

From"john james" <jj9801@nospam.com>
Date2015-04-01 06:59 +1100
Message-ID<co0cntF6jo5U1@mid.individual.net>
In reply to#14284

"Tim Watts" <tw_usenet@dionic.net> wrote in message 
news:vh2rub-54e.ln1@squidward.dionic.net...
> Please, no debates about the merits of this -
>
> I'm having trouble trying to find anything that might work.
>
>
> DNS based:
> ==========
> OpenDNS https://www.opendns.com/home-internet-security/
> is going to be tricky trying to make that work alongside Unblock-US which 
> is also DNS based. I might be able to track down the relevant Netflix 
> zones and declared them in my local DNS server and refer those to 
> UnblockUS whilst the default is to OpenDNS. In many ways though this is 
> the easiest solution, except that it has to work along side UnblockUS.
>
> No worries about the kids setting their own DNS servers, I'll deal with 
> that in the firewall :)
>
>
>
> Proxy
> =====
> eg Squidguard - It will not work with SSL traffic. Well, it might, but 
> then all my browsers will throw up man-in-the-middle warnings. Seems like 
> a non starter.
>
> Bloody big blacklist of IPs
> ===========================
> Assuming I can load several million into iptables without blowing up the 
> router (see below), this could work.
>
>
> Any approaches I've missed? Does not need to be perfect - just good enough 
> to mostly keep them off rotten.com, jihadist beheading vids and hard core 
> porn. And if they hack their way around it, good for them - at least they 
> are working for it - no illusions that they will be defeated for ever.
>
>
> Cheers
>
> Tim
>
>
>
> Equipment I have:
>
> Nice linux router running Debian 7 (this is are full blown nano system 
> with lots of RAM, not embedded). It is my PPPoE endpoint, firewall, 
> router, DNS, DHCP NAT and kerberos box.
>
>
> So I'd like to put 2 of my VLANs onto a filtered feed whilst leaving the 
> main VLANs unfiltered. My VLANs are like this:
>
> 1) Public IP /27 block
> 2) Private "Golden" 10.0.0.0/24 block
> 3) Media 10.0.1.0/24 block for Netflix etc - Chromecast, Roku and 
> phones/pads will use this
> 4) Guest net 10.0.2.0/24
>
> Each maps to a separate WIFI ESSID.
>
> 1+2 unfiltered
> 3+4 filtered all the time.
>
> Only difference between 3 and 4 is 4 can get a new password every few 
> weeks, without having to change Chromecast, Roku and other stuff.
>
> Assume the kids do not ever get to access 1+2.

Don’t forget who will be picking your nursing home. 

[toc] | [prev] | [next] | [standalone]


#14293

FromTim Watts <tw_usenet@dionic.net>
Date2015-03-31 22:13 +0100
Message-ID<n9frub-kpi.ln1@squidward.dionic.net>
In reply to#14290
On 31/03/15 20:59, john james wrote:
>
> Don’t forget who will be picking your nursing home.

I will...

[toc] | [prev] | [next] | [standalone]


#14294

FromCapitol <spam@wher.eva.co.uk>
Date2015-03-31 22:19 +0100
Message-ID<1JCdnX_9Yd62kobInZ2dnUVZ7smdnZ2d@brightview.co.uk>
In reply to#14293
Tim Watts wrote:
> On 31/03/15 20:59, john james wrote:
>>
>> Don’t forget who will be picking your nursing home.
>
> I will...

	Wishful thinking?

[toc] | [prev] | [next] | [standalone]


#14296

From"john james" <jj9801@nospam.com>
Date2015-04-01 09:46 +1100
Message-ID<co0mgeF9467U1@mid.individual.net>
In reply to#14293

"Tim Watts" <tw_usenet@dionic.net> wrote in message 
news:n9frub-kpi.ln1@squidward.dionic.net...
> On 31/03/15 20:59, john james wrote:
>>
>> Don’t forget who will be picking your nursing home.
>
> I will...

We'll see...

My dad thought that. He didn’t. 

[toc] | [prev] | [next] | [standalone]


#14297

FromTim Watts <tw_usenet@dionic.net>
Date2015-04-01 00:19 +0100
Message-ID<almrub-dln.ln1@squidward.dionic.net>
In reply to#14296
On 31/03/15 23:46, john james wrote:
>
>
> "Tim Watts" <tw_usenet@dionic.net> wrote in message
> news:n9frub-kpi.ln1@squidward.dionic.net...
>> On 31/03/15 20:59, john james wrote:
>>>
>>> Don’t forget who will be picking your nursing home.
>>
>> I will...
>
> We'll see...
>
> My dad thought that. He didn’t.

Hmm - the lack of "do it this way" responses suggests this needs a novel 
solution.

Thanks folks - just checking I was not missing something obvious.

OK - I think the final solution will maybe look like:

My DNS ->

Split views, ie a different view based on client IP (I do this already, 
nice feature of Bind9) -

VLAN 1+2 resolve normally.

VLAN 3+4 by default pass non local-authoritative queries to OpenDNS 
subscription service for filtering.

But I try to define zones for netflix.com (and any supporting ones, not 
sure it it uses akamai or similar, but a bit of tcpdum will tell me) - 
these zones are defiend locally as forwarder zones aka:

zone "netflix.com" IN {
     type forward;
     forwarders {
         <unblockus-DNS-servers>;
     };
};


I think that might work -

Only one way - just have to try it.

[toc] | [prev] | [next] | [standalone]


#14299

FromTim Watts <tw_usenet@dionic.net>
Date2015-04-01 16:30 +0100
Message-ID<rgftub-s28.ln1@squidward.dionic.net>
In reply to#14297
On 01/04/15 00:19, Tim Watts wrote:

> zone "netflix.com" IN {
>      type forward;
>      forwarders {
>          <unblockus-DNS-servers>;
>      };
> };
>
>
> I think that might work -
>
> Only one way - just have to try it.

This is very informative:

http://digiex.net/guides-reviews/guides-tutorials/networking-guides/11876-using-unblock-us-without-switching-dns-server-watch-netflix-outside-us.html

It looks like I will only have to subvert domain lookups for netflix.com 
and netflix.net.

Hmm - if the bind9 stanza above works, this could be very easy :)

[toc] | [prev] | [next] | [standalone]


#14303

FromJohn Rumm <see.my.signature@nowhere.null>
Date2015-04-01 23:50 +0100
Message-ID<NKydnSdVs5uo64HInZ2dnUVZ8hqdnZ2d@brightview.co.uk>
In reply to#14284
On 31/03/2015 18:36, Tim Watts wrote:

> Please, no debates about the merits of this -
>
> I'm having trouble trying to find anything that might work.
>
>
> DNS based:
> ==========
> OpenDNS https://www.opendns.com/home-internet-security/
> is going to be tricky trying to make that work alongside Unblock-US
> which is also DNS based. I might be able to track down the relevant
> Netflix zones and declared them in my local DNS server and refer those
> to UnblockUS whilst the default is to OpenDNS. In many ways though this
> is the easiest solution, except that it has to work along side UnblockUS.
>
> No worries about the kids setting their own DNS servers, I'll deal with
> that in the firewall :)

Sticking cache: in front of the google search usually does for many DNS 
blocks ;-)

> Proxy
> =====
> eg Squidguard - It will not work with SSL traffic. Well, it might, but
> then all my browsers will throw up man-in-the-middle warnings. Seems
> like a non starter.
>
> Bloody big blacklist of IPs
> ===========================
> Assuming I can load several million into iptables without blowing up the
> router (see below), this could work.
>
>
> Any approaches I've missed? Does not need to be perfect - just good
> enough to mostly keep them off rotten.com, jihadist beheading vids and
> hard core porn. And if they hack their way around it, good for them - at
> least they are working for it - no illusions that they will be defeated
> for ever.

If you still have the Draytek 2830, you can install (paid for extra) a 
filter in the router itself - that cuts off most of the available 
circumventions.


-- 
Cheers,

John.

/=================================================================\
|          Internode Ltd -  http://www.internode.co.uk            |
|-----------------------------------------------------------------|
|        John Rumm - john(at)internode(dot)co(dot)uk              |
\=================================================================/

[toc] | [prev] | [next] | [standalone]


#14307

FromTim Watts <tw_usenet@dionic.net>
Date2015-04-02 01:10 +0100
Message-ID<f1euub-ra9.ln1@squidward.dionic.net>
In reply to#14303
On 01/04/15 23:50, John Rumm wrote:
> On 31/03/2015 18:36, Tim Watts wrote:
>
>> Please, no debates about the merits of this -
>>
>> I'm having trouble trying to find anything that might work.
>>
>>
>> DNS based:
>> ==========
>> OpenDNS https://www.opendns.com/home-internet-security/
>> is going to be tricky trying to make that work alongside Unblock-US
>> which is also DNS based. I might be able to track down the relevant
>> Netflix zones and declared them in my local DNS server and refer those
>> to UnblockUS whilst the default is to OpenDNS. In many ways though this
>> is the easiest solution, except that it has to work along side UnblockUS.
>>
>> No worries about the kids setting their own DNS servers, I'll deal with
>> that in the firewall :)
>
> Sticking cache: in front of the google search usually does for many DNS
> blocks ;-)

Indeed - I just discovered a nasty in that google image search embed the 
porn^H^H^H^Hresults as data URIs in the HTML.

So OpenDNS cannot block them.

But there's a little known feature in Google in that if you set your DNS 
to resolve www.google.* to the CNAME forcesafesearch.google.com
then that does what it says - clever...

As for cache - good point.

I think you cannot get everything - but reducing the volume and ease is 
OK - mostly at this stage I want to remove the "by accident" factor...

>> Proxy
>> =====
>> eg Squidguard - It will not work with SSL traffic. Well, it might, but
>> then all my browsers will throw up man-in-the-middle warnings. Seems
>> like a non starter.
>>
>> Bloody big blacklist of IPs
>> ===========================
>> Assuming I can load several million into iptables without blowing up the
>> router (see below), this could work.
>>
>>
>> Any approaches I've missed? Does not need to be perfect - just good
>> enough to mostly keep them off rotten.com, jihadist beheading vids and
>> hard core porn. And if they hack their way around it, good for them - at
>> least they are working for it - no illusions that they will be defeated
>> for ever.
>
> If you still have the Draytek 2830, you can install (paid for extra) a
> filter in the router itself - that cuts off most of the available
> circumventions.

I did try that - and it looked interesting, but I've now dropped the 
Vigor in favour of a linux router as it was too buggy and alien to work 
with.

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.os.linux.misc


csiph-web