I have an initramfs script which knows half decription key and fetches the other half from internet.
My threat model is: I want to be able to dispose safely my drives, and if someone steals my NAS needs to connect it to a similar network of mine (same gateway and subnet) before I delete the second half of the key to get my data.


I switched to https://github.com/0xERR0R/blocky
Pihole was fine, but had features I didn’t care (mostly UI). Blocky is much smaller and lightweight