4 ms·
Ah yes, fullscreen horribad adverts that takeover your mobile screen. The entire page goes dark and some overlay ad has appeared on the news site you want to lo
by pakled_engineer 11y ago
Ah yes, fullscreen horribad adverts that takeover your mobile screen. The entire page goes dark and some overlay ad has appeared on the news site you want to look at either trying to get you to log in, buy something or download their app (full of ads) but you can't scroll around to find where the actual ad is to close the popup as the overlay is so far out of resolution it doesn't fit your device, so you just give up on the blacked out content.
The only solution I could come up with for Android/iOS was to run a remote digital ocean firewall to block all ads at the network level, and connect to it with a VPN. Everything else I've tried or implemented on the devices themselves ate up too much resouces or had to be dangerously elevated in privilege (NDK) just to stop the damn ads. A bonus of this method is you can also experiment with filtering known Android bugs before they reach your device if for whatever reason you can't update your system.img
- Khaine 11y agoThats why publishers and ad networks deserve whats coming. You reap what you sow. Mobile ads are the worst. They hijack the whole screen, float around make it impossible to view content, are a pain to dismiss, and they hijack scrolling. They are also highly likely to be a carrier for malware. Good riddance to such rubbish
- cheepin 11y agoI've been trying to think of a solution like this, but I'm not sure how to actually implement it. Do you know of any guides to do this?
- pakled_engineer 11y agoI run a VM with pf firewall (example book) https://www.nostarch.com/pf3 https://www.nostarch.com/pf3 which wholesale blocks known ad server IPs from adblock/ublock origin filter lists, other sources http://pgl.yoyo.org/adservers/ http://pgl.yoyo.org/adservers/ The firewall also prevents data leaks from misconfigured software phoning home or crash reports being sent, IPs being leaked over WebRTC, ect. You can also run your own DNS and email/backup server with the VM too. Then scrubbed traffic is passed to Snort (or use Suricata), with a ruleset to look for attack signatures. You can update rulesets from mailing lists https://lists.emergingthreats.net/mailman/listinfo/emerging-sigs https://lists.emergingthreats.net/mailman/listinfo/emerging-... and make your own by following whoever on Twitter is involved in Android/iOS security like @pof (Pau Oliva). There are specific mobile "emerging threat" rulesets too https://lists.emergingthreats.net/pipermail/emerging-sigs/2011-March/012298.html https://lists.emergingthreats.net/pipermail/emerging-sigs/20... Now you can install Ublock Origin on your phone browser and most of the work it has to do is already done saving memory and bandwidth. Here you can experiment with custom rulesets for how pages get displayed, whitelist certain objects you may wish to look at and not blindly block. To further go down the rabbit hole you can build your own mobile version of FF on your VM, ripping out all these harmful things: https://sites.google.com/a/chromium.org/dev/Home/chromium-security/client-identification-mechanisms https://sites.google.com/a/chromium.org/dev/Home/chromium-se... You can also set up a script on the VM to update Android on AWS. If say there's a new web views critical bug, and a patch is released your VM script (Ansible/Chef) can start an AWS instance, get the latest patch(s) and completely build a new system.img automatically. This can all be done with a custom app you write with the backend hosted on your VM, or with Termux or KBOX, and automate/abstract away all the ssh key logins and tasks with a script. Open your app see all available new Android patches, then click "Build" to automate your new system.img with your own signatures. Of course you don't have to use any of these tools, you could learn about their innards then roll your own software. If you are a javascript developer have the pf firewall dump it into your custom interpreter on the VM, that can look for unusual behaviour and just pass scrubbed js to your browser on the phone.
- anonred 11y agoOn iOS, using a PAC file (for wifi configurations) works quite well I've found.