Login
You're viewing the front-end.social public feed.
  • Oct 7, 2026, 6:20 PM

    BIG OL HOT TIP for folks like me using PiHole to block ads and trackers etc *and* devices on the latest iOS:

    You’re gonna want to turn off “Connectivity assist” right tf now.

    This feature used to be helpful when the wifi genuinely had no internet connectivity, but apparently iOS 27 uses it to *re-request DNS queries that failed because you intentionally blocked them*.

    This feature bypassed my filters for **132MB** of ads and trackers while I was hunting this down 🤬🤬🤬

    A screenshot of the iOS Wi-Fi settings showing the "Connectivity Assist" feature, with a data usage of 132 MB.
    💬 4🔄 7⭐ 1

Replies

  • Oct 7, 2026, 6:22 PM

    The ads themselves get served by neutral CDNs so this was 132MB purely of JSON and cookies over the span of… maybe 24 hours?

    I’m fuming…

    💬 0🔄 0⭐ 0
  • Oct 7, 2026, 9:30 PM

    @thure How does your resolver respond to a request for a blocked domain? I wouldn’t expect iOS to try again after getting an NXDOMAIN, but I could see that behavior for NOERROR or REFUSED (and obviously for SERVFAIL).

    💬 0🔄 0⭐ 0
  • Oct 7, 2026, 9:54 PM

    @bob_zim That’s a really good question, I’m seeing NXDOMAIN, IP, and NODATA on gravity-blocked queries, not sure how it’s choosing between them.

    Will look into these other response options, maybe that’s the trick.

    💬 1🔄 0⭐ 0
  • Oct 7, 2026, 11:10 PM

    @thure @bob_zim I posted about this earlier. I don’t think it’s simple as “I tried to resolve this ad IP and it failed so I’m trying again”. I use my local DNS to serve up local IPs and the assist feature was breaking valid domains with NXDOMAIN. If it were retrying but doing the resolution first, that wouldn’t happen.

    mas.to/@avidrissman/1173009084

    💬 1🔄 0⭐ 0
  • Oct 9, 2026, 3:17 AM

    @avidrissman @thure I remember a WWDC session from a few years ago in which they discussed TCP fast start (sending the request or TLS Client Hello in the body of the SYN; permitted by the standard, but rare for whatever reason) and … multi-path networking. I know the earlier WiFi Assist was whole-path switching. This behavior *could be* multi-path, but one of the paths can’t reach your private DNS server so it goes with some public server.

    I know systemd does something similar, which can result in very weird behavior if your configured DNS servers can’t all resolve the same names.

    💬 0🔄 0⭐ 0
  • Oct 9, 2026, 12:25 PM

    @bob_zim @thure In my setup, Tailscale is set up to override the DNS server entirely, no matter the network. It might be an iOS bug in which it doesn’t ask Tailscale to override in the Assist case, or this might be a Tailscale bug in that there is now a new case to handle and they don’t. I filed with Tailscale but the effect is the same for me, the end user.

    💬 0🔄 0⭐ 0
  • Oct 9, 2026, 5:30 PM

    @avidrissman @bob_zim I use Windscribe VPN as a PiHole-like blocker when not at home, and it does work as expected even with “connectivity assist” enabled – iOS does seem to honour however an active VPN resolves things.

    💬 0🔄 0⭐ 0
  • 💬 1🔄 0⭐ 0
  • Oct 8, 2026, 12:13 AM

    @jason I can see the queries in my PiHole’s logs, so iOS is clearly making the query, getting blocked, and then resolving it some other way when this setting is enabled. I just have the default resolver for cellular, unsure how I’d control that other than by using a VPN, so that’s probably how it’s getting around the queries I block on WAN.

    💬 1🔄 0⭐ 0
  • Oct 8, 2026, 12:31 AM

    @thure ok just checking. I DO route all traffic over my LAN (using wireguard), including DNS resolution, so I wonder if that would affect me. Still, an annoying setting to (surreptitiously?) re-engage…

    💬 0🔄 0⭐ 0
  • Oct 8, 2026, 1:46 PM

    @thure I’m not yet on 27, but I’ve prevented this leakage for a couple of years by using a WireGuard VPN to my home network when away from home and forcing all DNS resolution through it to my own filtering resolvers.

    💬 0🔄 0⭐ 0