16 ms·
The Brotherhood of the Ad Blockers
- djhworld 8y agoI've been running a Pi-Hole instance for about a year now, it's excellent. I could never get it to work with my router, but manually configuring the DNS on my devices to point to it works just as well. One thing that became immediately apparent was how much faster browsing the web got after I turned it on.
- FreeKill 8y agoAgreed, same for me. I did get it to work with my router as well, and it works amazingly well. When you supplement it with the community ban lists as well, it's incredibly powerful and updated quite frequently. Highly recommend it. Works great off a Raspberry-Pi.
- vsviridov 8y agoI resorted to having that PiHole to be my DHCP server and I turned off DHCP service on the router. It's a bit more fragile, but more flexible as well...
- vanadium 8y agoBeen running it myself for 5-6 months, and other than the occasional (actually, very rare) complaint from the Mrs. that a link she clicked won't go through due to a blocked tracker/analytics intermediary, it's been a peachy time VPNing into our home network so it works just as well on the go. Our install Pi-Hole points its upstream DNS to 1.1.1.1, with uBlock Origin where possible installed on our devices. Can't imagine going back.
- xenophonf 8y agoWhat advantage is there in using 1.1.1.1 instead of your own DNS resolver?
- a1369209993 8y agoSome ISP-provided resolvers fraudulently replace NXDOMAIN responses with NOERROR IN As pointing to (ironically, in this context) advertisment sites.
- xenophonf 8y agoI'm aware of the problems with ISP-provided resolvers. I meant running your own resolver, like named, which queries the root zones itself, supports DNSSEC response authentication, etc.
- a1369209993 8y agoIn that case: local resolvers involve actually installing and configuring a recursive dns server, which isn't everyone's idea of fun, whereas 1.1/8.8.8.8 can be set up with a one line config file edit and then forgotten about.
- mikestew 8y agoTo add to a1369209993's comment, an alternate DNS might be faster (as Cloudflare claims for 1.1.1.1), too. Or more stable than your default DNS. But for me, anyway, I made the switch after Frontier started pulling the NXDOMAIN stunt.
- fwn 8y ago...also censorship. Even my German ISP (Vodafone) apparently reroutes some URLs to servers they control. Solved it with DNS66.
- gruez 8y agoIs it me, or is pi hole way more popular than it should be? Compared to the alternatives, it's worse in almost every way. It only works on your local network, so good luck blocking ads while you're at work, using mobile data, or at a cafe. Browser based adblockers (which is available on most desktop browsers, mobile safari, and firefox for android) can block elements and url patterns, pi hole can't. Even if you're on a browser that can't use adblock (mostly android), you can still use VPN based adblockers (the ones that reroute your traffic through a local VPN), which work regardless of what network you're on. And worst of all, all of the alternatives are free, which can't be said for pi hole[1]. [1] I know you can run pi hole on your desktop OS, which is technically free, but you need to leave your computer on 24/7 which undoubtedly raises your electricity bill.
- johnvanommen 8y agoI thought you had to root your Android to block ads? In my household we have four people with smartphones and another four laptops. That's a lot of ads to block. Blocking ads on my laptop made a more noticeable improvement to web browsing than increasing my network bandwidth.
- sli 8y agoDNS66[0] can block ads without root. [0]: https://f-droid.org/en/packages/org.jak_linux.dns66/ https://f-droid.org/en/packages/org.jak_linux.dns66/
- Lionsion 8y ago> I thought you had to root your Android to block ads? Maybe with Chrome, but there's an Android version of Firefox that lets you install uBlock Origin: https://play.google.com/store/apps/details?id=org.mozilla.firefox&hl=en_US https://play.google.com/store/apps/details?id=org.mozilla.fi...
- deleted 8y ago[deleted]
- FreeKill 8y agoPi Hole is free, unless you're counting the system you have to run it off of (like a raspberry pi) but you can run it off any device you want like a virtual machine at home for instance, so you only need to buy a Raspberry Pi if that's how you intend to operate it. The benefit of it, is it blocks a lot more than just ads. For instance, it blocks any attempts to "phone home" by my smart TV or by applications I use such as Nvidia Geforce Experience. It's more extensive than browser based ad blockers because it works for your entire network, not just web browsing (for example, blocks all youtube ads on my un-rooted mobile device). It also has a huge set of customizable community maintained block lists that block everything from simple ads all the way to pornography (if that's what you want).
- ch4s3 8y agoDoes anyone know if there are performance penalties associated with using a Raspberry PI as your DNS server? Also, a link[1] to the Pi-Hole page. [1]https://pi-hole.net/ https://pi-hole.net/
- nasredin 8y agoUsing DNS blocking with Pixelserv on DD-WRT, 300 MHz single-core IIRC, there is no noticable performance hit.
- vanadium 8y agoNone. None at all that anyone's noticed in our home, and I imagine the speed associated with the fewer server requests and their payload offsets any negligible performance degradation that would have been there.
- craftyguy 8y agoSlightly off-topic, but from the pi-hole page: > Install by running one command: > curl -sSL https://install.pi-hole.net https://install.pi-hole.net | bash installing arbitrary software off the internet by piping curl output to bash is a terrible idea. At the very least, I would have expected them to sign this script... considering this software has unlimited access to your internal network, and the ability to influence ALL network traffic into/out of your internal network.
- iamatworknow 8y agoImmediately below that line on the pi-hole site: >Our code is completely open, but piping to bash can be dangerous. For a safer install, review the code and then run the installer locally.
- craftyguy 8y agoAnd yet piping to bash is being advertised boldly as the 'one-liner install process' In other news, eating rat poison might kill you, but there's a tiny warning printed on the back so no one will do ever do it.
- rb808 8y agoSurely the next step is for websites to host their own ads again? They can even forward cookies on to ad networks etc.
- AdmiralAsshat 8y agoHosting their own ads would at least force them to vet their own ads, which is ultimately what most people want, I think.
- tobltobs 8y agoWould be great if this would be an option, especially with the GDPR coming. But for small to medium sized publishers there are no ads you could host your own.
- orwin 8y agoThis is simply not true. i spoke two years ago with the CEO of a small publisher company (~3 employees). This company was focused on mobility, from train to skateboard, with cars being obviously the main focus. Affiliated links for small stuff like electric monocycles and/or sponsored tests for cars was enough to pay himself, his author, IT guy and tester.
- eli 8y agoIt also requires you to self-host an ad server (and most open source ad servers are terrible) and it requires the advertiser to completely trust your numbers since they'll have no way to verify how many impressions you served. That's tough right now even for people who sell ads directly.
- yoodenvranx 8y agoThe next step would be to do render the whole page including ads directly into a canvas/opengl element using some heavily obfuscated wasm binary in order to circumvent the DOM and any DOM/JS-based ad blocker.
- jbob2000 8y ago
- vsviridov 8y agoPiHole really needs to have a local DNS-over-HTTPS bridge. In some countries upstream providers do DNS poisoning for censorship purposes.
- corrigible 8y agoSomething like this[0]? [0]: https://bendews.com/posts/implement-dns-over-https/ https://bendews.com/posts/implement-dns-over-https/
- snake_plissken 8y agoPi-Hole is different from using a hosts file in that, Pi-Hole returns 200 OK with empty content for any requests to the black-listed domains?
- gruez 8y agohow does that work with https?
- 64kbisalluneed 8y agoJust install nginx that answers to http and https and return empty gif or 204.
- Chaebixi 8y agoWould that fail because your sever can't provide the right cert? You'd probably have to install a custom root certificate on your machines that you https ad blocker could use to forge certs.
- 64kbisalluneed 8y agoYes, custom cert has to be used, otherwise browsing could be very annoying.
- jordigh 8y ago> people who had an objection to capitalism in principle, Yes, citizens, watch your daily dose of ads or else the economy crumbles! For the good of capitalism, watch ads, citizens, watch ads!
- cfadvan 8y agoResume Viewing Gotta earn those 15 million credits!
- crunchlibrarian 8y agoI wonder if the backlash against advertising and social and the web more generally will lead to more people buying these sorts of devices to try and own their own networks and information again. Surely the cloud providers and the platforms will suffer in this shift.
- verdverm 8y agoI run grimd (alternative) in the cloud. Then I can point my router and dns app at it when I'm out and about. The setup needs upgrading for DNS over https and maybe run it in Kubernetes?
- dfee 8y agoFound it: https://github.com/looterz/grimd https://github.com/looterz/grimd Questions: 1) is this black hole concept sustainable? Or, does it require significant management, and is likely to be circumvented by serving content through a proxy anyway? 2) Why do you run this on the cloud? Don’t you then incur significant bandwidth costs? Or, if DNS only are there speed issues with your EC2 instance lagging?
- koolba 8y ago> Only a few years ago, even people who hated ads saw ad-blocking software as akin to stealing. I've been using ad blockers and NoScript plugins for longer than I can remember. Before that I was using /etc/hosts file based blocking. I've never felt like I was stealing nor do I know anyone that feels that way. On the contrary, I've always felt that content to display, and in particular code to execute, on my device is my decision and mine alone.
- darawk 8y agoDo you not believe that content creators have the right to set the terms upon which their content may be consumed? In other words, if you write an article, you don't believe that you have the right to say "you may read this article, provided that you also display this ad"? If you don't want to see the ad, simply don't read the article. What makes you think you have the right to the content, without abiding its terms? I say this as someone who uses an AdBlocker daily. Of course it's stealing. You're violating the contract you implicitly agree to when you visit the site. This may or may not have legal force, but it's clearly stealing. If you don't want to see ads, don't visit sites that have them. THAT is how you retain the sanctity of your experience and avoid stealing.
- logfromblammo 8y agoI'm going to need a Poe's Law check on this one. Sincere or satire?
- darawk 8y agoSincere.
- logfromblammo 8y agoContent creators have a privilege granted by copyright law to control the manner in which their work is distributed. Once the copy has passed to another, the law does not grant any further control over what the recipient may do with it privately. That is governed by explicit licensing terms. Websites may have a terms of use document that offers an adhesion contract for licensing the copyrighted materials served by the site. But such terms are not necessarily enforceable in every jurisdiction. And the onus is on the provider to enforce their licenses. Therefore, if the license contract states that a user may not read article X unless they also watch advertisement Y, it is in the site's interest to not serve X until after proof of Y has been returned. One cannot steal what was given freely. And it isn't exactly clear what remedy should be available to sites from users that breach an adhesion contract that has no technical measures implemented for enforcement. It isn't stealing. It is a civil licensing violation, at best.
- bxio 8y agoEver since I was given my first computer and was allowed on the internet, I've had NoScript and Adblock installed. I installed a Pi-hole last week, totally worth. Best amount of time and money I've spent so far this year.
- thejrk 8y agoHere it is! That comment that makes you feel old!
- textmode 8y ago"Alternative To /etc/hosts You don't have to use the hosts file (or addn-hosts ), but performance starts to suffer once the list of domains gets past 120,000. jacobsalmela says: June 24, 2015 at 06:53 It's partially due to the amount of domains on the lists controlled by the other sites. ~120,000 seemed to be the sweet spot. Once it got higher than that, the hosts format performed better. But a faster SD card can make a difference..." https://jacobsalmela.com/2015/06/16/block-millions-ads-network-wide-with-a-raspberry-pi-hole-2-0/ https://jacobsalmela.com/2015/06/16/block-millions-ads-netwo... The "list of domains" here is a list of domains to which the user does not want her computer to connect. The author is suggesting list sizes over 120,000 begin to trigger performance issues, using this dnsmasq-based approach. What about another "list of domains" that comprises all the ones to which the user does want to connect. Would it be more or less than 120,000? For over 15 years I have been running authoritative nameservers on the local network, using tinydns and later nsd, including a custom root. cdb, the key-value store used in tinydns, on its own is useful for storing domain->ipaddr mappings. I can store lists up to 4GB. If I understand correctly, the rough equivalent in Pi-Hole is perhaps serving /etc/hosts or some other list of hosts via dnsmasq. (I believe pdns_recursor can also serve /etc/hosts if I recall correctly.) IME, controlling both /etc/hosts and authoritative DNS has made it very easy to block ads since they almost always rely on DNS. However I use authoritative DNS as a substitute for recursive DNS. /etc/resolv.conf lists authoritative nameservers, not resolvers. As such, DNS is primarily used not to block but to selectively permit. (To build the zonefiles, I use a separate method for "prefetching" needed IP address in bulk that does not use recursive DNS. It has worked beautifully for over 15 years. On the local network I have encrypted DNS lookups via authoritative queries to CurveDNS-proxied authoritative nameservers; no recursive resolvers are needed.) Foregoing recursive DNS, the approach is similar to a firewall ruleset where the default is to block everything. The user then adds specific rules to allow desired traffic (or in this case domain resolutions). In other words, the approach I chose was to determine what domains I wanted to access instead of trying to identify every possible domain that needed to be blocked. Every domain is blocked by default until I allow it. Although I have no need for Pi-Hole personally I would like to see it succeed. I am glad to see that other users taking an interest in DNS. The reason I ask the question about the size of the "allow" domain list is that over 15 years I am not even close to reaching 120,000 domains. I wonder how many domains other users visit. To rephrase the question again: If there are two lists of domains: 1. all the domains to which the user wants to allow and 2. all the domains she wants to block, then which is the larger list? The answer will vary from one user to another.
- tannhaeuser 8y agoPersonally I have no problems with ads per se, it's the tracking, privacy, and security aspect I'm concerned about (and also the unbelievable bloatedness of ad-financed sites lately as ad prices race to the bottom). Personally I'd be fine with ads if we could go back to a content-oriented model where first-party static assets are served as ads rather than the targeted advertising we have now. I know others here who have zero tolerance for any kind of ads, though. Trying to grasp what a feasible business model for content creation could be, including paywalled content/micropayments as almost anything seems better than the clickbait and brainwash crap we have now.
- mikestew 8y agoit's the tracking, privacy, and security aspect I'm concerned about And that's what ads are, per se, in the 21st century. "Ads", as the current implementation defines it from my perspective, are no longer general-purpose and static. No, they chase you around the web and then for weeks will try to sell you the thing you just purchased. They'll load random executable code onto your machine. I, too, have no problem with a static JPG at the top of the screen, but that hasn't been what ads are in over a decade. Now the counter-argument would be, "but TV and print ads are not like that, so not all ads." Okay, fair argument though that might be, it's only because TV and print can't, and it's not for lack of trying. Print had the CueCat[0], TV has tried (and mostly failed), but those Samsung TVs are looking pretty creepy from what I'm reading. So to me, it's like saying, "I don't have a problem with authoritarian governments per se, it's all of the spying, control of the citizenry, and propaganda I have a problem with." Well, that kind of defines an authoritarian government, ergo... Anyway, I'm just being pedantic. Load up those ad blockers, and get Pi-hole running. [0] https://en.wikipedia.org/wiki/CueCat https://en.wikipedia.org/wiki/CueCat
- tannhaeuser 8y agoYes, and that's why I'm using an ad blocker, too. But the questions remains what is the Web going to look like as a mass medium when taking this to the extreme and there are only ads and propaganda left as rational incentives to publish content. Btw, you know you're on a site which occasionally does "native" advertising/promotions, if with decency? Also, think of tech coverage in the last decade or so; it's dominated by big media pushing their agenda aka the "consumerization of IT" (cloud stuff, Fb and Google web frameworks).
- ulzeraj 8y agoI run a similar setup that downloads the blacklist from some guy named Steven Black who wants to make the internet better and then I pipe it through sed to include them on my unbound resolver. The file is configured as an include on unbound.conf. #!/bin/sh PATH="/bin:/usr/bin:/sbin:/usr/sbin" rm -f /tmp/badsites wget https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts https://raw.githubusercontent.com/StevenBlack/hosts/master/h... -O /tmp/badsites if [ -f /tmp/badsites ]; then grep '^0\.0\.0\.0' /tmp/badsites | awk '{print "local-zone: \""$2"\" redirect\nlocal-data: \""$2" A 0.0.0.0\""}' > /etc/unbound/badsites.conf rm /tmp/badsites fi rc-service unbound reload
- yuhong 8y agoMy essay focuses on Google and DoubleClick specifically: http://yuhongbao.blogspot.ca/2018/04/google-doubleclick-mozilla-essay-final.html http://yuhongbao.blogspot.ca/2018/04/google-doubleclick-mozi...
- cdancette 8y agoI think we are slowly gaining consciousness about the danger of ads. It's really pernicious but I think has overall terrible effects on people (self estime, food / alcohol consumption...). And not just ads, but also product placement in movies / TV shows. I think it's terrible for our health and our minds.
- vertexFarm 8y agoAds aren't innocent anymore. As technology gets better they are getting far, far more persuasive. It's gonna get weird once it hits a crucial threshold of effectiveness and basically make public opinion counterfeit.
- darkkindness 8y ago> Publishers will target Salmela’s software if it becomes anywhere near as popular as AdBlock Plus, says Nicole Perrin, an analyst at researcher EMarketer. I'd caution about that claim. Google pulled AdNauseam[0], a uBlock Origin extension, from the Chrome Web Store since it was fundamentally disrupting Google's business model via click fraud. (It automates clicking ads in order to create noise in user tracking.) This was far, far before it became as popular as AdBlock Plus. PiHole takes an even more aggressive stance against ads, blackholing entire networks. It poses as much as a threat to the ad industry as AdNauseam. So I'd wager that PiHole will get shut down long before it reaches the popularity of AdBlock Plus. [0]: https://adnauseam.io/ https://adnauseam.io/
- lapnitnelav 8y agoI disagree with you : 1) Unlike AdNauseam, Google can't do much to get in the way of Pi-Hole. This isn't within its ecosystem. 2) Actually, while it's not great for publishers, it's not that disruptive (at that scale) because it doesn't impact the advertiser's ad spend. No request > No charge. Now if you wanted to create something that would be quite disruptive, you'd need to combine the 2, with a twist : You could have a headless browser in a VM (for safety) that makes some of those calls and mimic a click + follow the redirect + stay on the landing page and browse another N pages. Not every single ad obviously because that'd be easy to detect but at random, in an erratic way. That'd be like simulating an actual user. Throw in there some cookie dropping / reset to mess with tracking and it could have some pretty interesting effects. The reason why it'd more dangerous? Because it'd throw off performance of those ads and ML optimizations done by various vendors. Usually you expect a click-through rate (CTR) of 0.X % to maybe 2-3% and similarly an actual conversion rate in the single digits. On a large scale, you'd see a a CTR that either go up or stay on par, but a conversion rate that is free falling and that would have some serious consequences for both the advertiser's marketing team and the publisher / ad network. Take it one step further and have a TOR like network of those pi-holes taking care of that both to prevent device finger-printing and maybe coordinating a specific publisher / ad network / advertisers and you could see that advertiser looking at reducing its ad spend quite drastically when performance goes down the drain. And an ad network / publisher having to do some explaining. Some kind of "activist" bot network to force specific advertisers to reduce ad spending or simply occur costs.
- blueseaadmin 8y agoWould it not be possible to code either an add on or even a proxy server that "accepts" the ads, but sends them to /dev/null while serving up a "clean" rendering of a page? I'm sure this can be done.
- dbuder 8y agono one sees ad blocking as akin to stealing except the kind of people who will agree to any and all malware from their advertising networks without even a cursory glance.