4 ms·
What if I start a DNS service that blocks every ad server domainname in the "EasyList"? Personally I avoid using third party DNS, but if there is demand for th
by aplorbust 9y ago
What if I start a DNS service that blocks every ad server domainname in the "EasyList"?
Personally I avoid using third party DNS, but if there is demand for this...
- fjsolwmv 9y agohttps://adguard.com/en/adguard-dns/overview.html https://adguard.com/en/adguard-dns/overview.html
- aplorbust 9y agoWhat if I let the user run it locally? I point a local dnscache at a local, customised "root.zone" that blocks all these EasyList ad server domains? User could have several alternate root.zones that provide different "profiles". To switch profiles simply switch root.zones. (I used to do this for myself. Then I stopped using caches altogether. Now I do everything with tinydns, cdb and a customized stub resolver.) Or what if I resolve all the ad server domains in the EasyList each day from various checkpoints around the world and publish an IP blocklist? Then users can import it into their application level firewalls.
- srett 9y agoA good bunch of these resolve to AWS/cloudflare/etc. nowadays, so good luck with that.. :-/
- aplorbust 9y agoNo luck needed. Authoritative DNS makes it easy. Even without using authoritative DNS, if we only have a blocklist of IP addresses and some application-level firewall solution, we can examine outgoing HTTP headers in a client-side proxy and filter accordingly. I also do not use a popular browser that runs Javascript to send and retrieve to and from the internet. That is the root cause of most users problems. This is the most effective solution, bar none. The third parties users want to avoid are almost almost always depending on Javascript to accomplish their goals. Connecting a powerful interpreter with potentially full control over the users computer to the open internet. Then believing this can be safe. The user is granting use of this interpreter to third parties. In this thread we can see how users struggle to know which third parties can be trusted. All for the sake of keeping that interpreter open to "good" third parties to access at will over the internet. (Why is a good question.) Early web browsers called on other, separate programs to do specific jobs outside of rendering HTML. Taking a cue from that history, I use simpler, limited programs with no built-in interpreter to do two specific jobs: sending and retrieving. Third parties can return code in response to requests for content, but I am under no obligation to run the code, let alone run it from a popular browser with a powerful interpreter that is connected to the internet. Cannot speak for others, but this approach has worked well for me as the www worsens.
- culot 9y agoI've found that unbearably slow every time I've used it.
- josho 9y agoI do this on my home network. It works well, so I encourage you to build this out. As an added bonus As a service you could point the dns entries to your own web server and serve up cat pictures or motivational pictures in place of ads.
- DavideNL 9y agoNo need to build anything: https://pi-hole.net/ https://pi-hole.net/
- aplorbust 9y agoThe solutions I use were already "built" before this one existed. I was using djbdns to block ads before there were adblockers. I think its great that more users, through DNS-based ad blocking projects, may see how controlling their own DNS is useful, perhaps in ways they might not have imagined. However the last time I looked at it, I recall this project was defaulting to using open resolvers run by third parties, e.g. Google. Maybe I am remembering incorrectly since so many projects like to use these third party resolvers. In any event, that is not how my solutions work. A third party with such delegated (ultimate) authority from the user is not part of the solutions I designed for myself. Also, I never used dnsmasq as part of any solution. I have a strong bias against it for a number of reasons. If I recall correctly, pi-hole relies on dnsmasq.