4 ms·
Default settings use remote, shared DNS caches run by an advertising company. Regardless, this is a step in the right direction. DNS is highly effective for t
by gwu78 10y ago
Default settings use remote, shared DNS caches run by an advertising company.
Regardless, this is a step in the right direction. DNS is highly effective for this filtering out advertising.
Personally I just run my own authoritative nameserver(s) with all the IP addresses I need. No recursive cache.
When I browse to websites where I have never been and may not return, I am never using graphical browser that loads "resources" automatically from any random domain.
I am using a browser I compiled myself. I am only reading text.
Binary resources, e.g., video, can be downloaded non-interactively with an ftp/http client.
If it is an important website that I use repeatedly, then I have all the IP addresses for the resources the website's pages will need stored in a zone files. Then it is "safe" to use a browser written by an organization company that makes money from ads. All DNS requests are answered by my server(s).
I can retrieve (refresh) the IP addresses for my zone files very quickly with custom software I wrote to do this. My lookups are faster than a cold recursive cache and send out fewer requests.
IMO, the way to think about "ad-blocking" is not to try to imagine how to block every possible ad server. Instead, just focus on what web content you want and figure out what addresses you need to get it.
At one point a certain browser written by an advertising company had its own DNS resolver. Imagine your /etc/resolv.conf being completely ignored. Food for thought.
- pgrote 10y agoDo you find a setup like this takes more time to gather the information you're looking for? What is your primary reason for doing it this way? Privacy? Avoiding malware?
- gwu78 10y ago"Privacy? Avoiding malware?" Neither. Those benefits are only side effects.
- corney91 10y agoFor graphical browsers uMatrix is a good way to do this sort of thing. For every website you visit, you can tell it what resources from which domains to load and it'll block everything else.
- AlexAffe 10y agoI really like the approach. This is where the net is headed. Graphical browsing is unnecessary in a way. Now, the only issue with that is the way the web is currently heading. A site hosted at aws or cloudfront is hard to whitelist...
- gwu78 10y agoA domain like *.amazonaws.com has nothing to offer that I have ever seen, pure rubbish. Blocking it will stop ads in mobile apps. Cumulatively I think AWS is adding a hefty amount of latency. The way their DNS is configured is often convoluted, requiring excessive layers of gratuitous lookups. It sometimes borders on absurd, much worse than I have ever seen with CDNs. Fastly is doing a much better job with minimizing DNS queries. Certainly better than Akakami ever did.