You can do pretty much everything really easily with a pfSense appliance. Could run on a Pi as well I believe. Just my two cents. Added benefits are HAProxy for SSL termination (with automated letsencrypt support), business grade firewall, VLANS, and built in DNS/NTP/etc. Plus it's really easy to use/set up.
I was curious, I don't do the fake ntp reply DNS thing, but I do set the NTP DHCP option on my DHCP server. I'm not sure if this is respected by the HE Hub, but after looking through my firewall logs, I don't see any NTP requests to external servers.