Most definitely, although it of course depends on what else you're running on that VM. I have a home server running, among other things, a very similar setup [1] based on dnsmasq and a simple shell script cronjob, and the dnsmasq weighs in at ~12 MB memory usage (RSS).
The name has just kind of stuck, even though you can in fact run it on most linux distros (We officially support Ubuntu/Debian based distros, but there is limited support for Centos, and even forks for Arch, and Docker!), on a whole host of different hardware.
It's not officially part of the Pi Hole project, but I've been using https://hub.docker.com/r/diginc/pi-hole/ for about six months on a Raspberry Pi (though they support other platforms) and had no issues. They also keep up to date with new releases within a day or two usually.
I add this to my modem/wifi ap. and then just let every device use it to resolve. if the device allows to set a hostfile, I also add a local copy for when iam not in my network.
* GitHub - StevenBlack/hosts: Extending and consolidating hosts files from a variety of sources like adaway.org, mvps.org, malwaredomainlist.com, someonewhocares.org, yoyo.org, and potentially others. You can optionally invoke extensions to block additional sites by category. || https://github.com/StevenBlack/hosts
I take the hosts file approach to blocking on my VPN/DNS/Proxy servers.
I also add most Google/Facebook/etc domains to cut down on tracking and bandwidth from remote resources. Somehow the tentacles of Google (Analytics/Fonts/etc) and Facebook extend to most of the web. Their embedded javascript is everywhere. Blocking at the hosts file level seems to be the easiest and most convenient approach.
I used pi-hole until I got pfSense set up. Then I migrated to pfBlockerNG, which has a lot of the same DNS blocking capabilities built in. You may want to check it out.
Also, not sure how I feel about having this device as my primary DNS server for my entire internal network. What if the project gets compromised and injects a number of malicious DNS entries, now my entire network is toast?
To reliably run this DNS server I would have to have another host on the network that uses a separate DNS route that checks every entry on pi-hole against the secondary to confirm something fishy is not going on.
You can always review the code for yourself over on our github repo (https://github.com/pi-hole/pi-hole)! As well as the devs, there are so many pairs of eyes on the code that if anything fishy were to happen, everyone would know about it (not to mention it would completely undermine the hard work we've put into it over the past couple of years!)
Updates are manual, too, so unless you intervene, there is no reason that a working system would suddenly become compromised, except if somebody had access to your network. But then you have a different issue...
If you're going to manually audit the source, you can curl into a file then run bash on it. If you're not going to read the code anyway, there's no harm in curl|bash.
The compounds in this medicine are public knowledge, but taking them could be dangerous. For a safer experience, review all medical literature pertaining to these compounds before consuming.
Not really the same. One of the main issues with curl pipes is that the server (or MITM) can detect that the request goes into a pipe.
This allows an attacker to display one (safe) source when you view it in your browser on your workstation, or wget it, and serve a different (nefarious) source when you curl/pipe it.
So, a more complete analogy would be: a bottle that gives you a safe chemical compound when you extract it for analysis, but throws in some VX when you go to administer it.
Summary: Fill your script with an invisible payload that fills any buffers, and put something time consuming (say `sleep 5`) early in your script in order to detect that the script is being executed directly rather than just stored to disk. If the client halts before having read all data, it is likely a `curl | bash` scenario. If it just keeps reading, it's a regular browser just downloading.
That way, it is the same as running cURL without piping the output to bash, so people can easily check the code without worrying if the server is sending them different code when they pipe to bash
You acknowledge the prioritization of ease-of-use/adoption vs. security so I think we're on the same page.
I doubt step-by-step instructions including a review of the script's content would improve the average user's security, in much the same way that click-through ToS dialogs always garner such much scrutiny.
Edit: another comment quoted the warning on the page, at this point it feels like complaining is tilting at windmills.
I'm running HomeAssistant from an Odroid C2 --its working perfectly.
If you haven't checked out DietPi yet, you should. It includes optimized installations for a few hundred things (including PiHole), from Mumble servers, to MAME emulators.
Of particular added value there was mention of Android apps that can be setup to self-host an ad-blocking VPN / hosts filtering without rooting: https://news.ycombinator.com/item?id=13853408
Alas the plugin that does host-based blocking is not available in the play store version, it's/was a paid feature for the version on GH only. (edit: Don't know the current state though. remember from some time ago when I last checked it).
PiHole is pretty cool, very 'plug n play' which I like. A sufficiently advanced average user can set it up without too much trouble just following on a guide, even a relatively tech savvy 'lay' person can do this.
If you like a more technical solution I prefer something like running a Unbound + NSD server
Here's some great tutorials on that:
(Kudos to the people who write Calomel, i really liked these tutorials, it was a great way for me to get started and look into these services deeper once understanding what was going on here)
I'm really big into having ones own DNS server on the network instead of completely using outside solutions. There is little overhead with a sufficiently modern implementation.
Also, these solutions run on FreeBSD/OpenBSD for those who prefer.
As a complete aside. Aren't most routers, esp. business class routers, running modified Unix/Linux anyway? Why on earth hasn't a reputable company made a guns ready router that lets you have access to the Linux/Unix underpinnings without flashing (albeit awesome) Open Source alternatives? I would think in the 'business/enterprise' class hardware side this would be more prevalent.
Maybe I just don't know of any solutions like that available stateside. I found one in Europe:
I'm actually wondering if they simply didn't repackage this hardware with a better then average design for a case, frankly. The specs are very similar. I think even though these are AMD embedded processors they're ARM, not sure though, it didn't say (or i missed it).
How are people dealing with whitelisting when a website becomes broken because of an over zealous block. I find myself turning off ublock for some websites at least once a day, not because there are ads on the page but because they're issuing a dependency somewhere that has been blacklisted.
Yeah, first think I did after setting up pi-hole was go and visit all my primary sites, and see what was being blocked. Then white listed things I was OK with, or things that were breaking sites.
With all the ad blocking technologies that are coming up, I wonder if Google is devising something to counteract these efforts.
For instance, since browser-based ad blockers work from what I know by blocking known domain names, couldn't Google create random subdomains and serve the code from a different subdomain every day or even every few hours, as well as change the way their JavaScript and HTML looks?
Even something very expensive to run would be justified with all the money that advertising brings in.
If Google can create software that can tell what's in a picture, or if a person in a picture is happy or not, why can't they find a way to fool ad blockers..?
That's another good point. The people who are actively blocking ads are probably not the ones going to click them, even if they are not blocked. So not worth the money to invest in unblocking the ads going to people who aren't going to click them.
True. I am not meaning to say I am perfect (or that anyone can be), the hunch is just the expected click through rate of someone such as myself is likely much lower than someone who doesn't even know what an ad blocker is.
I think it's based upon the idea that people with ad blockers see less ads and so are still sensitive to ad impressions. In contrast, advertisements in really crowded situations (most people that walk about in urban areas, for example) require more effort to stand out as advertising saturation point hits.
I mostly combat any ad influence on me by making a point to _not_ buy anything that is advertised. Works out pretty well for helping me keep my sanity and conscience a little.
...? I think you're misreading my comment. I was suggesting that most people may think they are unaffected by ads, but probably are overestimating their immunity.
My second statement was highlighting how ones own opinion of oneself is not objective.
> My second statement was highlighting how ones own opinion of oneself is not objective.
And I retorted that ones own view of oneself can not be extrapolated onto the population at large if it is not objective.
But I should have been clear, when I mean "second statement" I mean so inside my own post. Ex:
1st Statement: "People," in this context, isn't defined either. If however we were to say that by "people" you mean millennials, then you would be wrong."
2nd Statement: "But if you meant "the population at large" you would be correct."
Which was in defense of the tech-literate and the young, but after researching some more my statements were based on old information.
The only people that come to mind who are easily susceptible to ads are the old and tech-illiterate, i.e those who don't have much experience with ads. Though this is just conjecture.
You would just block *.addomain.com at that point. Which is already what is being done on many of the blockers. There will always be domains to block, even if they add new domains, the blockers will probably be able to block them just as fast.
Sure, you could whitelist www.google.com, mail.google.com, etc, but couldn't they keep ahead of you if they were ok with using their main domain? They could even start using www.google.com/ad-id
Currently domain-based filtering is probably too small a proportion of traffic to even care about, but as ease-of-use comes to the masses there may come a point where the pro-ad side will implement this.
As far a I understand domain fronting works by sending a different host in the SNI header than later in the actual http request, thus hiding the actual requested host from an adversary watching the connection from the outside.
This would require cooperation from the sending http stack, in this case the browser. I doubt that this is a viable option in this case.
You really wouldn't want them on google.com/something since restricting cookies to sub-uris is a painful mess. Subdomains is slightly easier, but also easier to block.
There has been a - now defunct - working group which tried to address the issue of setting cookies on sub URIs: https://www.w3.org/TR/csp-cookies/ Particularly interesting is the proposal by someone from Akamai: https://lists.w3.org/Archives/Public/public-webappsec/2013Se... to include a path scope for cookies. I don't know if there are any more recent developments on cookies and their scope policies.
What if the New York Times decided to host all ads themselves? nytimes.com/ad-42.jpg couldn't be distinguished from nytimes.com/todays-front-page-image.jpg
Obviously it's more likely for ad ad-provider like Google to do this, but even then, if there's new content from Google (say a blog post) I expect to be able to see it.
I'm pretty sure that /ad-.jpg or something like that is already a blocking pattern. But you're correct: I'm seeing ads on some smaller sites that host the ad banners on their own servers. And you know what? I'm okay with this. I explicitly use uMatrix instead of uBlock since blocking trackers and malware is more important to me than blocking ads. (Getting rid of the more annoying ads is a bonus, though, and I might change my mind if first-party ads become annoying, too.)
Safari itself is an ad-blocker, with its "reader mode". I could hardly imagine opening a newspaper page without it. Actually, my iPad 2 isn't powerful enough anymore to open a newspaper page, except if I use the reader mode.
Firefox as well. I use Pocket as a perferred reader generally, though its failure to provide a means of navigating directly to sites, or of showing a navbar, is annoying.
(Pocket ... has multiple annoyances. It's better than the alternatives, so far as I've tried, but that is one hellaciously low-set bar.)
Ad blockers do a lot more than just block domains. They look for and remove divs/DOM elements that contain known ad naming schemes and remove them from the page.
And if a site decides to start combating the ad blockers, the adblock list providers will update their rules specifically for the site in question. Adblock users get upset whenever they see ads, and report them pretty quickly.
The business I work for tried blocking adblockers and after a bit of back and forth they trumped us by blocking all AJAX requests on our site. We gave in after that.
When over 30% of your userbase is adblocking, it's not worth it. Your users will complain to you, not the adblockers. They don't even understand what's going on. Asking your users to whitelist the site doesn't work, either.
I thought "hey, the Newsletter and Security Notices icons aren't clickable", opened a ticket, and found that the input and submit elements that should be under those icons were being blocked by disconnect.me :)
It seems like a lot of the "Show HN" shares do that kind of thing...from domains that my work blocks. If it sounds really cool I'll load it up on my phone. Otherwise, that's a great way to make me decide "not worth my time" and move on to the comment thread.
To me, that would be a sign that you are winning the battle. If enough websites fight ad blockers, especially big sites, and the people behind those ad blockers make clumsy mistakes, then users will reach a point where they uninstall the blocker.
Does it matter if they stop visiting the site? Considering that they are using resources without giving something back in return? I guess it could be argued that they might be promoting the site to other users.
Other than that, they are essentially freeloaders and if a website has too many freeloaders it has to either get rid of them or convert them to something else. Or, I guess, the website could shut down completely.
If you're going to pirate a movie, you're probably not buying that movie. This is why on the whole piracy doesn't actually affect bottom line that much. Sure some folks would have rented it from their cable provider for $6 or whatever, but on the whole if you're going through the trouble of finding a good torrent and downloading it, you're not in the market to spend money on it.
Just the same, if you have an adblocker installed it's unlikely you're the type of person who is going to be clicking on ads anyway. And PPC ads are much, much more prevalent than impression-based ads. So if someone is blocking your ads, you're not losing anything. You get paid when someone clicks an ad, and if they're going to the trouble of blocking all ads, they're not clicking anything anyway.
You create a system where they won't or can't visit your site, and your traffic decreases, which will have an effect on your ad rates.
Impression ads are important for certain industries and bigger publications. I will agree that PPC ads are common in other areas and ad blocker users wouldn't click them. For impression advertising the ad blocker will result in lost income. PPC ads are the option of last resort for an established publisher because they are almost like gambling.
>Considering that they are using resources without giving something back in return?
Funny. Ads are consuming CPU time and electricity that I pay for in addition to my attention and time, and compromise my decision making. To me, any of those are infinitely more valuable than resources the website expends on serving ads or trying to.
Does it matter if they stop visiting the site? Considering that they are using resources without giving something back in return?
Buzz. I block ads but I also post links to articles on social media that are then followed by people who do not block ads.
I have a couple of areas of focus where I am exceptionally knowledgeable and people who have anything more than a passing interest in those subjects check out links I post.
Or, I guess, the website could shut down completely.
You can have all the ads you want, but if people aren't visiting your site - and sharing links to it, talking about what they read there, recommending it to others - they're not going to get you much revenue.
> people behind those ad blockers make clumsy mistakes
What "mistake?" That the developers couldn't foresee and block the exact elements against ad-blockers before they became real?
Reading the parent comment, it seems users are not opposed to reporting specific instances for the greater good. This is obviously more energy consuming than uninstalling, so where do you get the idea people will all of a sudden stop using an adblock because it failed to get passed one or two sites?
We're already seeing anti-ad-blocker-blockers being developed to remedy this problem. And if they don't come fast enough, users can just turn off their adblock for one page and be done with it.
Direct advertising is a dying legacy tactic. The most successful ads these days are the ones you can't tell are ads. They're also the stronger poison of the two.
It sounds like the people behind the ad blocker broke Ajax for that website while trying to block the ads - that's the mistake I am referring to.
You mention that native ads are gradually replacing direct ads as if it's a good thing. The good guys in the publishing industry go out of their way to prevents ads affecting content, they don't allow their writers/presenters etc to touch advertising and everything is clearly separate.
In the long term, ad blockers will just push out those people who are driven by ethics and you'll be left with the sleazy publications that are driven by PR. This is coming from someone who has dealt with PR agencies and constantly turned down proposals.
> It sounds like the people behind the ad blocker broke Ajax for that website while trying to block the ads - that's the mistake I am referring to.:
> The business I work for tried blocking adblockers and after a bit of back and forth they trumped us by blocking all AJAX requests on our site. We gave in after that.
I took this to mean that adblockers had to evolve and block AJAX on the website to make it accessible. Not, that they were hasty and disabled all functionality.
> You mention that native ads are gradually replacing direct ads as if it's a good thing.
On the contrary: "The most successful ads these days are the ones you can't tell are ads. They're also the stronger poison of the two."
> The good guys in the publishing industry go out of their way to prevents ads affecting content, they don't allow their writers/presenters etc to touch advertising and everything is clearly separate.
I didn't know this. However, I think it's a losing game. Consumers don't seem to care too much about the "good guys," unless a moral campaign is spear-headed (a la Tesla by The Oatmeal), only not seeing ads at all.
It's ironic really. We block ads so we're not influenced by them, but then we lower our guards and become susceptible to the indirect kind.
It's the natural order anyway. There will be those in the coming generations that will be like just like us. Except where we fought against direct ads, they will fight against the indirect. There've always been those unorganized who value critical analysis in all contexts, but their findings and ways never reach the public and make any impact.
Or maybe we've just made ourselves out to be sheep. As long as the coyotes aren't around, out of sight out of mind.
> In the long term, ad blockers will just push out those people who are driven by ethics and you'll be left with the sleazy publications that are driven by PR. This is coming from someone who has dealt with PR agencies and constantly turned down proposals.
As is with all things. You do not survive by being ethical, but by being the most adaptable, and sociopathy happens to be a great adaptation for sales.
I'm more interested in what happens next after the sleaze epoch. Will ads continue to become more and more manipulative then, finally after reaching too far, begin to wither and fade into the anals of history (albeit likely not as known as it should be, because of "out of sight out of mind."). Or will someone finally shake up this industry?
For informational sites, I'll block sites that violate my preferred conditions, and load them up in third-party tools, e.g., Archive.is, on the rare occasion I find an interest in their content.
Yes, that's why I also mentioned changing the HTML. For instance, change the ID of the div that contains the ad. It could even be random and change every time.
I don't have experience fighting ad blockers, though (I actually enjoy my ad blocker).
If Google did it, I doubt ad blockers would be able to block all ajax request on Google, or everyone would simply uninstall the extension.
The most promising front against ad blockers is forcing users to access your content with an application you control. That's why more and more websites want you to install their apps (Google search is installed by default on lots of android devices). It's very unfortunate that the incentives of users and content creators / advertisers aren't aligned very well and we will probably end up with most content creators dumbing down their web experiences in favor of better mobile applications.
I think pi-hole will at least partially block such things -- it intercepts at the network level. I guess you could have the app break itself if the ads won't load, but you can (mostly) do that in a browser.
I guess, for network level ad blockers, I'm not seeing obvious advantages to a program written as an app vs a program written to run in a browser.
As others have mentioned, you could just serve ads and content from domains which you wouldn't want to block, like www.google.com. And if an app receives its content encrypted (eg. SSL) you can't do a lot of filtering at the network level apart from domain names.
True. I want to be able to add my own root ssl cert to my phone for this exact reason. Then it will think that my MITM adblock proxy is the real deal. This should work great for web browsers. It does get a bit nastier for apps.
That's an immediate way to lose my eyes. I hate using my phone when I don't have to, and I hate installing site-specific apps even more. I'm already using a computer with a nice screen, mouse, and keyboard. Why would I want to use something with a tiny screen and touch input instead?
I think Google can save ads about as effectively as AOL can save dialup. Probably their plan is to just milk advertising until the last Windows 95 computer dies too.
Unfortunately, ads pay for a lot of web content just like they pay for most TV content.
The 5% (of which pretty much all of HN is a part of) can probably afford to pay for the cost of creating that content. The 95%, consisting of not just hourly wagers but also salaried folks generally can't afford to. The trade off is ad supported content.
Something like 2/3 of millennials are blocking ads which means Google has already encountered just about everyone willing to consume their advertising. Ad-supported websites would be unprecedented if anyone really cared about them not having to find a new way to make money. Nothing truck drivers want is going to make driving trucks a career forever either.
Decreasing ads will hurt sites that aren't providing enough value I guess. Maybe others that could but were fragile. Cynically a natural selection of some sort.
- Google Chrome for mobile doesn't allow add-ons so you can't install ad-blockers. (You can install browser extensions with Firefox for Android.)
- Google Chrome uses a dark pattern where the address bar tends to send users to the Google search results page instead of to their final destination (compare the behavior with Firefox's). That means that even if you have an ad-blocker, many users are likely to click on Google ads on the way to the destination site, even if they are blocked on the destination site.
- Android doesn't provide fine-grained permissions control or root access, so users can't block ads.
- Some of their content is designed to coerce users to buy restricted Android-based content-consumption devices. For example, you can't buy movies on YouTube and watch them HD in Google Chrome (at least on my computer). You have to buy another computer that doesn't have root access (an Android device) in order to consume the videos in HD. Once you're on the restricted device, it's harder to block ads.
- Google introduces projects like AMP that try to convince webmasters to restrict their monetization options and make it easier to appify the WWW. AMP even serves your content from Google's servers. The more control of the content they have from server-to-eyeball, the more options they have for stopping ad-blockers (and the worse it is for open technology).
- Android apps like YouTube and Google News use a built-in browser frame to show navigated-to web pages, rather than opening them in an external browser. The built-in frame uses Chrome tech, without add-ons. They used to allow you to open links by default in an external browser, but not any more.
> The built-in frame uses Chrome tech, without add-ons
To block ads in Chrome Custom Tabs [1][2] you can either use Chromer [3] to change the custom tab provider to Brave [4] or use the article mode in Chromer.
Just a happy user and not affiliated, but Brave was a hallelujah-moment for me. Never got Firefox to be especially fluid, not even close to Chrome. But Brave, IIUC, takes Chromium and adds some adblocking. It's not perfect, and some ads makes its way in, but it removes quite a lot while still being very snappy. To the best of my knowledge and experience, I can really recommend it.
Now I just hope that Brave doesn't turn out to be too evil :S.
> You have to buy another computer that doesn't have root access.
It's called HDCP, and I believe it's a combination of your GPU, monitor and cable between it supporting it. Netflix and most other online streaming services do this too. It has nothing to do with root access.
Ad-Away (installable via F-Droid if you are rooted) allows you to block ads at the hosts-file level, which will work in Chrome and in other apps that display ads.
Before anyone chews me out, as this effectively renders many free apps equivalent to their premium (ad-free) counterparts, I usually pay for said premium versions to compensate their developers.
The catch here is that it isn't as good - using uBlock in FF for Android for example will properly block all ad frames.
Using adaway or a pi-hole for that matter will not - they will only cause ad loading to fail (in some cases) - which sometimes results in frames showing errors on the page instead of a clean rendering of nothing with ad divs removed.
Personally I wind up using several methods - AdAway to kill most app ads, uBlock for web and Xposed to kill YouTube ads since the hosts-based methods seem to work rather poorly for them as their subdomains change all the time.
DNS-level blocking is, IMO, only a second line of defense. Nice to have for all those devices and applications where you cannot have a proper ad/tracking/malware blocker.
> - Android doesn't provide fine-grained permissions control or root access, so users can't block ads.
One caveat here - Google devices are probably some of the most allowing of root access and full device ownership - easily unlocked bootloaders basically allow it to be a one button process.
Some manufacturers make you put your device on a shitlist with them before they'll give you a key to unlock the bootloader and root it - others, like Apple, won't allow you to at all.
Once you are rooted, you do have full ability to block everything and get fine-grained permission control via XPrivacy for example. Android devices are actually some of the best here mostly due to strong community support. You can't even get this control if you want it on many mobile devices these days.
I've never seen a way to root my phones without some risk of turning them into bricks. How would I quickly and safely get root access to a Galaxy Note III without risking the destruction of the device?
Samsung is an example of a manufacturer that doesn't make it easy. Oppo, One Plus and Google (LG) all have very easy to unlock bootloaders that have "official" instructions from the manufacturer (and it's two commands away).
Can you still brick it? Yes. Is it likely if you type the two commands as you're told to on the website? No.
The Note 3 is not a Google-made device, it's made by Samsung. Google's own Nexus and Pixel devices allow it in a single button press, I'm unsure of other manufacturers except OnePlus which does the same as Google. As I said in my post, some devices are a lot better than others when it comes to this.
Also, bricking doesn't just happen, if you understand what you're doing you'll be fine. That "some risk" isn't random, it's in the case that you do something incredibly stupid. Get a custom recovery on there as soon as possible and you can pretty much recover anything.
This is simply not true. I've spent 3 years flashing and messing with my phone in many ways.I've hard bricked it only once. When it was updating my phone froze.
I didn't do anything stupid. It simply froze and messed with all partitions. It's hard to fuck your phone but it's a possibility.
Sorry, but "froze and messed with all partitions" makes it sound more like you fucked up and flashed the wrong rom or something - flashing an update should never mess with all partitions - only /system and /data really.
Use magisk or suhide and they'll work just fine. When you have access to the bootloader, there's nothing they can do to stop you - any attempt will ultimately be futile.
From what I've seen, there are no actual cases of this in practice at least not on Google devices - Google devices don't even have such a fuse. Maybe some Samsung stuff - but that's an easy fix, don't buy from Samsung. Also, it does not fail SafetyNet even on those Samsung devices, just some Samsung-specific stuff.
From what I've seen the only mention of such fuses on Google devices is one that enables secure boot from factory and forces you to run the unlock command as I mentioned to reflash your bootloader - nothing to do with safetynet or anything similar.
Let me know if I'm missing a device which does actually do this. Yes, it's theoretically possible, but requires sufficient crypto hardware and protection to make it significant and it'd be a significant shift in direction for Google to go this route currently in my opinion.
Of course a full safetynet emulation that would spoof the check as a different device would also be an option... but it'd be a pretty big undertaking, but one which I'm sure would happen if this ever became a remotely significant threat.
And yet Apple introduced a first-class ad blocking mechanism into iOS that even works in 3rd party apps (using SFSafariViewController). There are dozens of ad blocking apps available on the App Store, which are much more accessible to the average user than having to root your device and install apps that have full root privileges.
Yeah, that's definitely a step in the right direction, I certainly wouldn't say that Google does nothing to protect their interests in advertising - especially given their recent actions on the Chrome store with AdNauseum.
However, what I'm trying to get at is that, for example on iOS you still can't block in-app non-Safari ads at all. On Android you can do that if you want to, and a lot more, you can also block specific connections, block device-specific identifiers, APN lists, accelerometers, wake state, etc - it's a better compromise for someone concerned about privacy than other platforms even with this considered right now.
Seems like one could block google's DNS servers -or perhaps even all DNS requests not destined for your pi-hole server in this example- on the router side and the Chromecast will fallback to what DHCP is providing.
I believe Pi Hole have tried to block YouTube Ads but Google randomise the domains they serve those ads from, and also from what I have read, they also serve some fundamental features via those domains too. So if you kill the ads, you kill YouTube.
Could youtube-dl the video then redirect the browser to a locally-served (locally from the pi-hole device, that is) page embedding the video, provided you've got the disk space to cache it and don't mind waiting a bit for the video to download (admittedly a lot of caveats here, but could work for many people). That'd actually be a better experience for most sites youtube-dl supports, I'd think, not just Youtube.
The web advertising firm I work for has random looking domains for that purpose. The current domain generation algorithm seems to be using one to two domains a month. Although I've don't have access to any of the frontend code, I can only assume the DOM elements on the page are also obscured/randomized to an extent.
It is also my understanding that some of our boxes are here solely to proxy requests (either assets or websockets, which are increasingly popular in the field) to 3rd parties, to make sure it bypasses client side countermeasures.
I've been running a DNS based ad blocking for ages, but I realized that recently, youtube has been serving ads from the same domain as regular videos. I wonder if anybody has seen this.
Using this at home. Really interesting to see the blocked domains on the dashboard. Realised my two Samsung Smart TV's were constantly calling home for example. You'll eventually whitelist some things that break like Spotify/Sonos IIRC.
I may switch to an Odroid C2 if I go with a permanent VPN connection as the throughput of the RPi3 network port is not the best.
When I tried pi-hole I often noted some urls were added 'automagically' to the whitelist, they will show up a few days after I removed them. All of them were weird domains.
Pi-hole Dev here. The only domains added to the whitelist are the domains on which the source lists are themselves hosted. It's probably complete over-kill, but the reasoning behind it is just in case one list tried to blacklist another.
Looks like your comments were getting killed with [dead] automatically. Maybe because of a new HN account combined with linking to the same site a couple times cause it to flag some spam detector? I vouched for your comments so they appear. Thanks for the project!
I went so far as to set up Dnscrypt with a pi-hole setup recently and it was almost as painless as advertised. And it finally gave me something productive to do with my RPi3! https://github.com/pi-hole/pi-hole/wiki/DNSCrypt could use a little wordsmithing, but it wasn't too bad.
I have to admit to doing as little as possible from web browsers on phones, but on the desktop I rely extensively on uMatrix + NoScript (don't know if adding PrivacyBadger on top would buy me anything). However, NoScript for Android seems to be moribund and I don't think there is a uMatrix for Android either. DNS-based ad-blocking seems very 90s (i.e., designed for an era that's less invasive than today), and there's a ton of javascript content that really needs to be filtered as well if you want to counter all the ads + tracking. Is there any equivalent to NoScript + uMatrix on Android?
I only have uBlock Origin on Firefox for Android, as opposed to uMatrix on desktop Firefox. It's better than nothing wrt tracking blocking, and it kills most of the ads.
I've been doing this at home for probably close to 10 years or so, set up manually using dnsmasq, and periodically fetching new blacklists. Nice to see it wrapped in a tidy package--great work.
I haven't had time to look at the code yet. I have some questions though.
As an experiment a while back I wrote a simple dns server that blocked ad-related domains. https://github.com/geuis/lead-dns. While it technically worked, it made using the web almost non functional. Nearly every site was broken in some way. So blocking purely by domain isn't going to work. I wonder how pi-hole is dealing with it.
We have a web interface with a whole host of tools to easily identify and whitelist the domains that may or may not be causing issues with sites you browse.
Everyone's mileage varies, but I have only had to whitelist 5 or 6 sites using the default blocklists.
319 comments
[ 0.17 ms ] story [ 314 ms ] threadI don't see any reason why this wouldn't run well on a pi-zero. It doesn't do much beyond DNS.
[1] https://github.com/majewsky/system-configuration/blob/bf0f2b...
Is there a docker container for it already, by any chance?
The name has just kind of stuck, even though you can in fact run it on most linux distros (We officially support Ubuntu/Debian based distros, but there is limited support for Centos, and even forks for Arch, and Docker!), on a whole host of different hardware.
Also github project explains https://github.com/pi-hole/pi-hole
http://someonewhocares.org/hosts/
I add this to my modem/wifi ap. and then just let every device use it to resolve. if the device allows to set a hostfile, I also add a local copy for when iam not in my network.
Direct link:
https://raw.githubusercontent.com/StevenBlack/hosts/master/h...
Also, I think OpenDNS blocks ads too. Haven't tried it in a few years though.
* Home Internet Security | OpenDNS || https://www.opendns.com/home-internet-security/
I also add most Google/Facebook/etc domains to cut down on tracking and bandwidth from remote resources. Somehow the tentacles of Google (Analytics/Fonts/etc) and Facebook extend to most of the web. Their embedded javascript is everywhere. Blocking at the hosts file level seems to be the easiest and most convenient approach.
You can just apt-install it.
Its pre-alpha, but it might work for you...
https://github.com/time4tea-net/py-hole
Also, not sure how I feel about having this device as my primary DNS server for my entire internal network. What if the project gets compromised and injects a number of malicious DNS entries, now my entire network is toast?
Updates are manual, too, so unless you intervene, there is no reason that a working system would suddenly become compromised, except if somebody had access to your network. But then you have a different issue...
Yes, I know this is supposed to be a convenience thing, but I wish people wouldn't actively encourage this pattern.
`curl -sSL https://install.pi-hole.net`
It's only 1400 lines of code.
At least it has TLS to prevent a MITM
I can't stop people from doing potentially dangerous things, but I don't have to promote those things, either.
You cannot look at version history, check a signed package, etc. etc.
If someone wants to root just a few select machines, you would want people to do a curl install.
> Our code is completely open, but piping to bash can be dangerous. For a safer install, review the code and then run the installer locally.
This allows an attacker to display one (safe) source when you view it in your browser on your workstation, or wget it, and serve a different (nefarious) source when you curl/pipe it.
So, a more complete analogy would be: a bottle that gives you a safe chemical compound when you extract it for analysis, but throws in some VX when you go to administer it.
To combat this sort of thing, @jbenet made hashpipe: https://jbenet.github.io/hashpipe
Summary: Fill your script with an invisible payload that fills any buffers, and put something time consuming (say `sleep 5`) early in your script in order to detect that the script is being executed directly rather than just stored to disk. If the client halts before having read all data, it is likely a `curl | bash` scenario. If it just keeps reading, it's a regular browser just downloading.
That way, it is the same as running cURL without piping the output to bash, so people can easily check the code without worrying if the server is sending them different code when they pipe to bash
Anyway, if you decide to live on the edge.. don't copy-paste: http://thejh.net/misc/website-terminal-copy-paste
I doubt step-by-step instructions including a review of the script's content would improve the average user's security, in much the same way that click-through ToS dialogs always garner such much scrutiny.
Edit: another comment quoted the warning on the page, at this point it feels like complaining is tilting at windmills.
Why do you care so much about what people do or don't do?
Edit: We're talking about blocking ads, right? If people encouraged everyone to block ads what would happen to the economy?
I'm trying to find other services that are worth running in a similar fashion. Any ideas?
I have never used Tor though, and I can't say I know the consequences of running a relay. So I'd probably skip that.
If you haven't checked out DietPi yet, you should. It includes optimized installations for a few hundred things (including PiHole), from Mumble servers, to MAME emulators.
HomeAssistant looks interesting too.
Set up a cheap cloud hosted adblocker in an hour for $2.50 a month
https://news.ycombinator.com/item?id=13852109
Of particular added value there was mention of Android apps that can be setup to self-host an ad-blocking VPN / hosts filtering without rooting: https://news.ycombinator.com/item?id=13853408
https://github.com/M66B/NetGuard
NetGuard is the first free and open source no-root firewall for Android.
Optionally block ads using a hosts file (not available if installed from the Play store)
I re-linked NetGuard as the most user-friendly, but https://github.com/julian-klode/dns66 was also mentioned.
If you like a more technical solution I prefer something like running a Unbound + NSD server
Here's some great tutorials on that:
(Kudos to the people who write Calomel, i really liked these tutorials, it was a great way for me to get started and look into these services deeper once understanding what was going on here)
https://calomel.org/nsd_dns.html
https://calomel.org/unbound_dns.html
Pairing that with squid proxy can be the ultimate win:
https://calomel.org/squid.html
https://calomel.org/squid_adservers.html
https://calomel.org/squid_ua_random.html
and don't forget dnscrypt people!
https://dnscrypt.org/
I'm really big into having ones own DNS server on the network instead of completely using outside solutions. There is little overhead with a sufficiently modern implementation.
Also, these solutions run on FreeBSD/OpenBSD for those who prefer.
As a complete aside. Aren't most routers, esp. business class routers, running modified Unix/Linux anyway? Why on earth hasn't a reputable company made a guns ready router that lets you have access to the Linux/Unix underpinnings without flashing (albeit awesome) Open Source alternatives? I would think in the 'business/enterprise' class hardware side this would be more prevalent.
Maybe I just don't know of any solutions like that available stateside. I found one in Europe:
https://omnia.turris.cz/en/
Can't get it stateside though :(
I instead custom built most of my networking hardware...but still.
Maybe you can get some alternatives based on those cards.
Thanks for the link!
For instance, since browser-based ad blockers work from what I know by blocking known domain names, couldn't Google create random subdomains and serve the code from a different subdomain every day or even every few hours, as well as change the way their JavaScript and HTML looks?
Even something very expensive to run would be justified with all the money that advertising brings in.
If Google can create software that can tell what's in a picture, or if a person in a picture is happy or not, why can't they find a way to fool ad blockers..?
But in the end you probably won't win against someone who really hates ads. - and that's probably better for users as well as advertisers.
Sure, I believe that I am pretty much completely unaffected ads, but then so does almost everybody else.
Is it because you believe people use ad-blockers because they're impulsive and can't hold their gaze?
I mostly combat any ad influence on me by making a point to _not_ buy anything that is advertised. Works out pretty well for helping me keep my sanity and conscience a little.
This is in the same vein of inductive reasoning as "just snap out of your [insert mental illness/addiction/etc.]."
"People," in this context, isn't defined either. If however we were to say that by "people" you mean millennials, then you would be wrong.
But if you meant "the population at large" you would be correct.
Although, the second statement is tangential to the article at hand.
My second statement was highlighting how ones own opinion of oneself is not objective.
And I retorted that ones own view of oneself can not be extrapolated onto the population at large if it is not objective.
But I should have been clear, when I mean "second statement" I mean so inside my own post. Ex:
1st Statement: "People," in this context, isn't defined either. If however we were to say that by "people" you mean millennials, then you would be wrong."
2nd Statement: "But if you meant "the population at large" you would be correct."
Which was in defense of the tech-literate and the young, but after researching some more my statements were based on old information.
The only people that come to mind who are easily susceptible to ads are the old and tech-illiterate, i.e those who don't have much experience with ads. Though this is just conjecture.
It's like saying "sure, I think think that I'm smarter than everybody else, but then so does everybody else."
My point was that people should not take their own assessment of themselves as strong objective evidence about themselves.
Sure, you could whitelist www.google.com, mail.google.com, etc, but couldn't they keep ahead of you if they were ok with using their main domain? They could even start using www.google.com/ad-id
Currently domain-based filtering is probably too small a proportion of traffic to even care about, but as ease-of-use comes to the masses there may come a point where the pro-ad side will implement this.
This would require cooperation from the sending http stack, in this case the browser. I doubt that this is a viable option in this case.
What if the New York Times decided to host all ads themselves? nytimes.com/ad-42.jpg couldn't be distinguished from nytimes.com/todays-front-page-image.jpg
Obviously it's more likely for ad ad-provider like Google to do this, but even then, if there's new content from Google (say a blog post) I expect to be able to see it.
You could whitelist the search results page and nothing else.
Viewing a blog post is less important IMO.
www.google.com/dog-595984hdfh/
www.google.com/cat21/
Current browser-based blocking tech would be rendered useless, right?
(Pocket ... has multiple annoyances. It's better than the alternatives, so far as I've tried, but that is one hellaciously low-set bar.)
And if a site decides to start combating the ad blockers, the adblock list providers will update their rules specifically for the site in question. Adblock users get upset whenever they see ads, and report them pretty quickly.
The business I work for tried blocking adblockers and after a bit of back and forth they trumped us by blocking all AJAX requests on our site. We gave in after that.
I thought "hey, the Newsletter and Security Notices icons aren't clickable", opened a ticket, and found that the input and submit elements that should be under those icons were being blocked by disconnect.me :)
Who does that leave?
Other than that, they are essentially freeloaders and if a website has too many freeloaders it has to either get rid of them or convert them to something else. Or, I guess, the website could shut down completely.
Just the same, if you have an adblocker installed it's unlikely you're the type of person who is going to be clicking on ads anyway. And PPC ads are much, much more prevalent than impression-based ads. So if someone is blocking your ads, you're not losing anything. You get paid when someone clicks an ad, and if they're going to the trouble of blocking all ads, they're not clicking anything anyway.
You create a system where they won't or can't visit your site, and your traffic decreases, which will have an effect on your ad rates.
Funny. Ads are consuming CPU time and electricity that I pay for in addition to my attention and time, and compromise my decision making. To me, any of those are infinitely more valuable than resources the website expends on serving ads or trying to.
Buzz. I block ads but I also post links to articles on social media that are then followed by people who do not block ads.
I have a couple of areas of focus where I am exceptionally knowledgeable and people who have anything more than a passing interest in those subjects check out links I post.
Or, I guess, the website could shut down completely.
The tragedy of the commons.
You can have all the ads you want, but if people aren't visiting your site - and sharing links to it, talking about what they read there, recommending it to others - they're not going to get you much revenue.
What "mistake?" That the developers couldn't foresee and block the exact elements against ad-blockers before they became real?
Reading the parent comment, it seems users are not opposed to reporting specific instances for the greater good. This is obviously more energy consuming than uninstalling, so where do you get the idea people will all of a sudden stop using an adblock because it failed to get passed one or two sites?
We're already seeing anti-ad-blocker-blockers being developed to remedy this problem. And if they don't come fast enough, users can just turn off their adblock for one page and be done with it.
Direct advertising is a dying legacy tactic. The most successful ads these days are the ones you can't tell are ads. They're also the stronger poison of the two.
You mention that native ads are gradually replacing direct ads as if it's a good thing. The good guys in the publishing industry go out of their way to prevents ads affecting content, they don't allow their writers/presenters etc to touch advertising and everything is clearly separate.
In the long term, ad blockers will just push out those people who are driven by ethics and you'll be left with the sleazy publications that are driven by PR. This is coming from someone who has dealt with PR agencies and constantly turned down proposals.
> The business I work for tried blocking adblockers and after a bit of back and forth they trumped us by blocking all AJAX requests on our site. We gave in after that.
I took this to mean that adblockers had to evolve and block AJAX on the website to make it accessible. Not, that they were hasty and disabled all functionality.
> You mention that native ads are gradually replacing direct ads as if it's a good thing.
On the contrary: "The most successful ads these days are the ones you can't tell are ads. They're also the stronger poison of the two."
> The good guys in the publishing industry go out of their way to prevents ads affecting content, they don't allow their writers/presenters etc to touch advertising and everything is clearly separate.
I didn't know this. However, I think it's a losing game. Consumers don't seem to care too much about the "good guys," unless a moral campaign is spear-headed (a la Tesla by The Oatmeal), only not seeing ads at all.
It's ironic really. We block ads so we're not influenced by them, but then we lower our guards and become susceptible to the indirect kind.
It's the natural order anyway. There will be those in the coming generations that will be like just like us. Except where we fought against direct ads, they will fight against the indirect. There've always been those unorganized who value critical analysis in all contexts, but their findings and ways never reach the public and make any impact.
Or maybe we've just made ourselves out to be sheep. As long as the coyotes aren't around, out of sight out of mind.
> In the long term, ad blockers will just push out those people who are driven by ethics and you'll be left with the sleazy publications that are driven by PR. This is coming from someone who has dealt with PR agencies and constantly turned down proposals.
As is with all things. You do not survive by being ethical, but by being the most adaptable, and sociopathy happens to be a great adaptation for sales.
I'm more interested in what happens next after the sleaze epoch. Will ads continue to become more and more manipulative then, finally after reaching too far, begin to wither and fade into the anals of history (albeit likely not as known as it should be, because of "out of sight out of mind."). Or will someone finally shake up this industry?
Almost universally, it's not worth it.
I don't have experience fighting ad blockers, though (I actually enjoy my ad blocker).
If Google did it, I doubt ad blockers would be able to block all ajax request on Google, or everyone would simply uninstall the extension.
* Security/Guidelines/Web Security - MozillaWiki || https://wiki.mozilla.org/Security/Guidelines/Web_Security#Co...
Mozilla makes a good tool to let you scan and report on this sort of thing for any site.
* Observatory by Mozilla :: Scan Results for news.ycombinator.com || https://observatory.mozilla.org/analyze.html?host=news.ycomb...
I guess, for network level ad blockers, I'm not seeing obvious advantages to a program written as an app vs a program written to run in a browser.
The 5% (of which pretty much all of HN is a part of) can probably afford to pay for the cost of creating that content. The 95%, consisting of not just hourly wagers but also salaried folks generally can't afford to. The trade off is ad supported content.
So it's very unlikely to die off.
- Google Chrome for mobile doesn't allow add-ons so you can't install ad-blockers. (You can install browser extensions with Firefox for Android.)
- Google Chrome uses a dark pattern where the address bar tends to send users to the Google search results page instead of to their final destination (compare the behavior with Firefox's). That means that even if you have an ad-blocker, many users are likely to click on Google ads on the way to the destination site, even if they are blocked on the destination site.
- Android doesn't provide fine-grained permissions control or root access, so users can't block ads.
- Some of their content is designed to coerce users to buy restricted Android-based content-consumption devices. For example, you can't buy movies on YouTube and watch them HD in Google Chrome (at least on my computer). You have to buy another computer that doesn't have root access (an Android device) in order to consume the videos in HD. Once you're on the restricted device, it's harder to block ads.
- Google introduces projects like AMP that try to convince webmasters to restrict their monetization options and make it easier to appify the WWW. AMP even serves your content from Google's servers. The more control of the content they have from server-to-eyeball, the more options they have for stopping ad-blockers (and the worse it is for open technology).
- Android apps like YouTube and Google News use a built-in browser frame to show navigated-to web pages, rather than opening them in an external browser. The built-in frame uses Chrome tech, without add-ons. They used to allow you to open links by default in an external browser, but not any more.
To block ads in Chrome Custom Tabs [1][2] you can either use Chromer [3] to change the custom tab provider to Brave [4] or use the article mode in Chromer.
[1] https://developer.chrome.com/multidevice/android/customtabs
[2] https://www.reddit.com/r/Android/comments/5ahlfq/dev_psa_chr...
[3] https://play.google.com/store/apps/details?id=arun.com.chrom...
[4] https://play.google.com/store/apps/details?id=com.brave.brow...
Now I just hope that Brave doesn't turn out to be too evil :S.
It's called HDCP, and I believe it's a combination of your GPU, monitor and cable between it supporting it. Netflix and most other online streaming services do this too. It has nothing to do with root access.
Before anyone chews me out, as this effectively renders many free apps equivalent to their premium (ad-free) counterparts, I usually pay for said premium versions to compensate their developers.
Using adaway or a pi-hole for that matter will not - they will only cause ad loading to fail (in some cases) - which sometimes results in frames showing errors on the page instead of a clean rendering of nothing with ad divs removed.
Personally I wind up using several methods - AdAway to kill most app ads, uBlock for web and Xposed to kill YouTube ads since the hosts-based methods seem to work rather poorly for them as their subdomains change all the time.
That's weird, I didn't get any Youtube ads in quite a long time, and only use AdAway.
Defense in depth.
One caveat here - Google devices are probably some of the most allowing of root access and full device ownership - easily unlocked bootloaders basically allow it to be a one button process.
Some manufacturers make you put your device on a shitlist with them before they'll give you a key to unlock the bootloader and root it - others, like Apple, won't allow you to at all.
Once you are rooted, you do have full ability to block everything and get fine-grained permission control via XPrivacy for example. Android devices are actually some of the best here mostly due to strong community support. You can't even get this control if you want it on many mobile devices these days.
Can you still brick it? Yes. Is it likely if you type the two commands as you're told to on the website? No.
Also, bricking doesn't just happen, if you understand what you're doing you'll be fine. That "some risk" isn't random, it's in the case that you do something incredibly stupid. Get a custom recovery on there as soon as possible and you can pretty much recover anything.
On Android devices with unlocked bootloaders, a great amount of apps won't work.
Android Pay, Snapchat, Pokémon Go, etc.
Google has tried to fight rooting as much as possible.
So, yes, they can do something: blow fuses in the fucking system.
From what I've seen the only mention of such fuses on Google devices is one that enables secure boot from factory and forces you to run the unlock command as I mentioned to reflash your bootloader - nothing to do with safetynet or anything similar.
Let me know if I'm missing a device which does actually do this. Yes, it's theoretically possible, but requires sufficient crypto hardware and protection to make it significant and it'd be a significant shift in direction for Google to go this route currently in my opinion.
Of course a full safetynet emulation that would spoof the check as a different device would also be an option... but it'd be a pretty big undertaking, but one which I'm sure would happen if this ever became a remotely significant threat.
However, what I'm trying to get at is that, for example on iOS you still can't block in-app non-Safari ads at all. On Android you can do that if you want to, and a lot more, you can also block specific connections, block device-specific identifiers, APN lists, accelerometers, wake state, etc - it's a better compromise for someone concerned about privacy than other platforms even with this considered right now.
Did you hear about SafetyNet? https://koz.io/inside-safetynet/
IP (and BGP) are ultimately concensus realities.
AMP
Before that I would be bombarded by ads for every video and then in the middle of any video that ran more than 30 minutes.
I don't mind a few ads I get the concept but 95% of the ads were just two companies Wix and Grammarly over and over.
It is also my understanding that some of our boxes are here solely to proxy requests (either assets or websockets, which are increasingly popular in the field) to 3rd parties, to make sure it bypasses client side countermeasures.
Looks like someone has shut the Pi-hole.
https://github.com/friimaind/pi-hole-droid
I may switch to an Odroid C2 if I go with a permanent VPN connection as the throughput of the RPi3 network port is not the best.
Compare the "automagical" whitelist entries (http://imgur.com/a/rxgsC) to the Default whitelist here: https://github.com/pi-hole/pi-hole/blob/master/adlists.defau...
Edit: The code that does it: https://github.com/pi-hole/pi-hole/blob/master/gravity.sh#L2...
Thanks for vouching for me :)
You got hit by a spam filter; they're tuned more aggressively for new accounts. We've marked this account legit so it won't affect you again.
such as?
Also, if you click the timestamp you should see a [vouch] link. Clicking that helps too.
(Disclaimer: I am the author of nogo)
2. Prevent sites from manipulating the list via CSRF.
3. Packages/Installers with installation as a service/daemon would be a plus.
As an experiment a while back I wrote a simple dns server that blocked ad-related domains. https://github.com/geuis/lead-dns. While it technically worked, it made using the web almost non functional. Nearly every site was broken in some way. So blocking purely by domain isn't going to work. I wonder how pi-hole is dealing with it.
Everyone's mileage varies, but I have only had to whitelist 5 or 6 sites using the default blocklists.