Secure DNS Bypasses Parental Controls Website Blocking

Secure DNS Bypasses Parental Controls Website Blocking

Secure DNS Bypasses Parental Controls Website Blocking
Secure DNS Bypasses Parental Controls Website Blocking
9 hours ago
Model: Deco BE63  
Hardware Version:
Firmware Version: 1.1.7 Build 20250342 Rel. 32980

I recently purchased a Deco BE63 mesh system and have been setting up the parental controls. I believe my hardware version is US/2.6 and the firmware version is reported as 1.1.7 Build 20250342 Rel. 32980. 

 

It looks like the website blocking feature is based on DNS and not actively filtering individual requests. I set up discord[dot]com as well as several other discord related sites to be blocked but it was not working in either Firefox or Edge web browsers. I didn't understand why this would not work and saw the discord[dot]com showed up in the visited website list with a "BLOCKED" icon next to the entry.

 

To investigate further, I opened up a CMD prompt and tried to ping discord. I saw that the returned IP address was 10.0.0.1 which is a non-routable address and the ping attempt failed. Next, I went to look in the browser settings for Edge and Firefox and saw that by default they will use their own secure DNS servers for address lookup. In this case, totally avoiding how the Deco parental controls blocks websites. I've changed the browser internal DNS settings to not use any available secure DNS server and just resolve the addresses locally and now discord is blocked by not resolving. 

 

I hope that TP-Link will look at other ways to block website access besides DNS lookups. I think a lot of users will not know to investigate and disable the secure DNS lookups in computer web browsers.

 

Cheers,

David

  0      
  0      
#1
Options

Information

Helpful: 0

Views: 8

Replies: 0