43 ms·
Pi-Hole: Why You Need a Network-Wide Ad-Blocker
- adrianN 8y agoI like the idea of running a Pi-hole, but my crappy ISP provided router is unreliable enough as it is, I don't really want to add a second layer of software that can break. So I'll just stick with UBlock.
- deleted 8y ago[deleted]
- Fnoord 8y agoI can recommend to buy your own router instead (e.g. Turris Omnia/Mox or Ubiquiti EdgeRouter series) and put your provider's in bridge mode. If you're from the EU, you might be able to compel your ISP to do just that.
- dingaling 8y agoI also prefer a blocking list and blocker on each terminal device rather than central on the network. It is unpleasant otherwise to open one's laptop at the library or at a friend's house and be bombarded by ads.
- mnw21cam 8y agoThis is the single greatest argument against getting a Pi-hole.
- j0hnml 8y agoYeah, this is a valid point. But, you can also just keep something like uBlock installed and just disable it when using pi-hole and then enable it once you’re on something like a public network.
- Tomte 8y agoWhy disable uBlock? I have both Pi-Hole and uBlock Origin active.
- badbug 8y agoYou can do both
- schappim 8y agoThe install process is curling a script into bash: curl -sSL https://install.pi-hole.net | bash :-)
- daef 8y agohttps://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- smittywerben 8y agoCurl bash is fine [0]. Even Windows tools do this now [1]. That said, if you're a linux admin you shouldn't copy-paste r̼̯ḁ͙̬̕n̪͍̯d̳̦͓̜͉͜o̴̳m̳͚ ̡̭s̜̦̣̠̀h͓̲i̼̫̮̗̜t̜̗̜̪̬̲͟ anyways. [0] https://brew.sh/ https://brew.sh/ [1] https://chocolatey.org/install#installing-chocolatey https://chocolatey.org/install#installing-chocolatey
- bigiain 8y agoThey do at least call it out in the writeup as being poor form. But they don't explain why or offer any alternative...
- ziftface 8y agoThey do have an official docker image, that's a pretty good alternative in my opinion.
- steevdave 8y agoMaybe they added it after you read it, but when I read the post they specifically mention it's bad and provide a link to read more on why it's bad. Sure an alternative would be great but the point of the article is to get up and running with the pi-hole software so they went with the fastest install.
- WaLLy3K 8y agoWhat we need is for the blog to explain things as nicely as the GitHub repo does - unfortunately, it's a topic that's a bit hard to concisely explain in one line. Repo explanation: https://github.com/pi-hole/pi-hole#one-step-automated-install https://github.com/pi-hole/pi-hole#one-step-automated-instal...
- phito 8y agoI tried pihole once, but it made my whole network incredibly slow... Also I can't setup the DNS on my router :(
- fyfy18 8y agoI like the idea of Pi-hole but I had the same thing, even though I was running it on a VM much more powerful than a Raspberry Pi.
- la_oveja 8y agowhy is it based on the raspberry when it has so terrible network interface? literally a +6 year board with a cual core and a gigabit interface can do this for better.
- dev_dull 8y agoIt’s just resolving dns queries. What types of resources do you think it needs? Also, newest revision of rpi (model 3 b+) is quad core 1.4ghz with gigabit lan. Overkill for a project like this.
- Jaruzel 8y ago> with gigabit lan Although, tests have shown it's not really gigabit in speed, but it is faster than the old 100mbit NICs previous Pis.
- Fnoord 8y agoIIRC the bus of the NIC is shared with USB which is USB (v2) which is 480 Mbps or about half of 1 Gbps. If you care about throughput, don't use the USB ports when you care about it. But either way, 100 Mbps is more than fine for a Pi-Hole. I'd worry more about any possible latency overhead.
- hrktb 8y agomostly nitpicking, but it's not gigabit lan; the interface is limited by internal bus to 300Mbs It doesn't matter if you dedicate it to this single use, you'll see more lag if it's also doing file serving stuff in the background for instance (also because of CPU use, not just networking)
- corobo 8y agoI have it running on an Ubuntu virtual machine on my NAS. You can probably run it on whatever 6 year old board you like https://discourse.pi-hole.net/t/hardware-software-requirements/273 https://discourse.pi-hole.net/t/hardware-software-requiremen...
- 8y ago
- comprev 8y agoI've been running Pi-Hole for a while now installed on the same RPi as XBMC. Occasionally I bump into false-positives and PH blocks legit websites.
- guu 8y agoI had issues with Pi-Hole slowing down page loads significantly until they introduced NXDOMAIN and NULL blocking as an option. These features made it to the stable build this week so it might be worth trying again for those who had issues in the past.
- moviuro 8y agoI do it differently on my own DNS ad blocker: it returns the IP of my "happy" webserver that always returns `204 No Content`, whatever query you send to it. Of course, there's still the issue of https failing, but I've never had any performance issues - much more the opposite actually. I wrote a tiny bit about how I do it: https://try.popho.be/byeads.html https://try.popho.be/byeads.html
- Jaruzel 8y agoMy experience with Pi-Hole is that there are too many sites that detect that their adverts and tracking scripts don't load and refuse to let you in. It's really hard to white-list for a site in Pi-Hole, as it's blocking for the whole network, so finding what domains you need to unblock is quite laborious. Additionally, if you are not around, and a family member or co-worker can't get to a site then they have no way to bypass it unless they also know how Pi-Hole works. Personally, I find a browser based advert/tracking blocker add-on to work better. If Pi-Hole had a webpage where you could put in a domain, i.e. cnbc.com, and it went off and loaded the html of that page, worked out all the other domains that html connects to, and then gives you a 'unblock' button to click, that would improve usability significantly, as even a non-techie user could use it.
- xg15 8y agoGenerally, I agree - though I imagine the advantage of pi-hole is that it can also block ads in non-browser contexts, e.g. mobile apps. At least it can until those apps start to use their own hardwired DNS/DoH server...
- Sol- 8y agoI would have the same concern, I imagine the Pi-Hole is best for households only inhabited by tech-affine people. I installed the uBlock Origin addon for some family members and even there they can be easily confused when a website breaks due to it (occurs rarely, but it happens). At least there I can easily tell them to temporarily disable ad-blocking by pressing that big uBlock button. I don't think it would be feasible for me to explain to them how to temporarily whitelist things on the Pi-Hole.
- starquake 8y agoYou can add a button to your Raspberry Pi to temporarily disable all the blocking. Not the best solution but still useful to know I think.
- arnjerobben 8y agoDo you have a link to a tutorial?
- binbag 8y agoI could be on the wrong track here, but the MACE ad-blocker built into the PIA VPN seems to work very well by itself. It's not free like PiHole is, but pretty cheap, and a VPN is probably a better starting point for security than a local blocker. Am I missing something here?
- jaxn 8y agoI have a VPS with an Outline VPN that I use. I'm going to try to put PiHole on there and see if I can get it to work.
- Fnoord 8y ago> and a VPN is probably a better starting point for security than a local blocker. Am I missing something here? Why? A VPN is just another (S)POF. I'm not afraid my ISP will MITM me. With a VPN, who knows what they log or not? Also, OpenVPN's performance is terrible. If you want to avoid detection of BitTorrent, sure, but then just route only that over a VPN. If your ISP MITMs you, and you're paying them, consider to jump ship. I see uBlock being mentioned throughout this thread. uBlock Origin is (very) nice, but its client-side overhead and you can't use it on "apps". What I do is catch all DNS requests and forward them to my DNS-based adblocking (I basically run Pi-Hole on an ER-L) and forward that to DNS over TLS (which works with Quad9). This is all used even if I'm roaming (via WireGuard, ie. very low overhead). So it is irrelevant which network my roaming clients use.
- binbag 8y agoThe performance of my network is certainly not terrible when connected to the VPN. Download speed is not noticeably affected and my ping to quake servers (I run VPN all the time, even while gaming) is often lower with the VPN connected. Regarding your 'why is it more secure' question - because I live in the UK where the government and a myriad of its approved bodies are now allowed to look at user traffic and see my IP and what websites I've visited. I don't have to worry about that now - although yes I need to trust that PIA really are not logging.
- 8y ago
- JumpCrisscross 8y agoFor some reason, I was reminded of the message iOS’s original top-selling as blocker posted when pulling their app [1]. (TL; DR They felt bad about denying advertisers their revenues.) While the web is gnarly and unforgiving, we’ve progressed—as a culture—in our general treatment of ads and ad blockers. [1] https://marco.org/2015/09/18/just-doesnt-feel-good https://marco.org/2015/09/18/just-doesnt-feel-good
- rangibaby 8y agoWhat an odd thing to feel bad about. > People are taking the piss out of you everyday. They butt into your life, take a cheap shot at you and then disappear. They leer at you from tall buildings and make you feel small. They make flippant comments from buses that imply you're not sexy enough and that all the fun is happening somewhere else. They are on TV making your girlfriend feel inadequate. They have access to the most sophisticated technology the world has ever seen and they bully you with it. They are The Advertisers and they are laughing at you. You, however, are forbidden to touch them. Trademarks, intellectual property rights and copyright law mean advertisers can say what they like wherever they like with total impunity. Fuck that. Any advert in a public space that gives you no choice whether you see it or not is yours. It's yours to take, re-arrange and re-use. You can do whatever you like with it. Asking for permission is like asking to keep a rock someone just threw at your head. You owe the companies nothing. Less than nothing, you especially don't owe them any courtesy. They owe you. They have re-arranged the world to put themselves in front of you. They never asked for your permission, don't even start asking for theirs. Banksy
- javajosh 8y agoWonderful quote. The concept I have been playing with I call "consensual communication". We dont allow people to run up to us and shove food in our mouths, and yet we allow information to be shoved into our minds - and as the quote notes, they have the gall to place restrictions on the object of assault.
- xg15 8y ago
- corv 8y agoIs there a way I can keep a second DNS as a fallback that doesn't get used unless my pi-hole is down?
- nirav72 8y agoYes. Just set your secondary dns in your client to whatever dns you were using before. It will fall back on secondary if primary dns via pihole fails.
- corv 8y agoSometimes the secondary will take precedence over the primary even though pi-hole is reachable.
- WaLLy3K 8y agoIn my experience, Windows is the worst offender for this. *Nix, macOS and iOS will always prefer the first resolver if all other variables (ping, availability, etc) are equal.
- pbhjpbhj 8y agoI can't remember the details but something changed in Ubuntu defaults to make default to distribute the DNS calls rather than order nameservers, it can be set to use order preference. In short, don't assume strict ordering on Ubu, at least.
- Mashimo 8y agoSure. I put in your second DNS as .. seconds DNS. My routers DHCPD gives pi-hole as primary and itself as secondary DNS.
- corv 8y agoIt seems that both primary and secondary are being used in round-robin and the primary gets relegated when secondary happens to answer faster.
- ramshanker 8y agoWhen I am on home wifi, no ads in my mobile thanks to PiHole. So many apps are filled with ads while on the move. Clearly pihole version of web feels more snappy. There are apps serving the App Add tiles BEFORE they load real content from their own far-away (by latency) servers.
- Tomte 8y agoI love how the Protestant Church of Germany has a very good installation description on their web site: https://datenschutz.ekd.de/2018/04/12/pi-hole-ein-erfahrungsbericht/ https://datenschutz.ekd.de/2018/04/12/pi-hole-ein-erfahrungs...
- dvfjsdhgfv 8y agoI found this bit interesting: > After meanwhile four weeks "leisure mode" of the Pi-hole in my network this comes up stately 12245 DNS inquiries, of which 7102 DNS inquiries were blocked. That's 58%. It's interesting, if not surprising, that six of the top 10 blocked domains come from Microsoft, two from Google, and one each from Amazon and Vungle.com.
- erikbye 8y agoIf you block Windows telemetry domains and run Windows, naturally those domains will be at the top... I have a lot of blocklists, but I think one of the default ones includes Windows telemetry. watson.telemetry.microsoft.com 15110 v10.vortex-win.data.microsoft.com 11338 fls-na.amazon.com 4397 nexus.officeapps.live.com 3547 settings-win.data.microsoft.com 3463 collector.githubapp.com 3396 www.google-analytics.com 3379 www.googletagmanager.com 2246 www.googletagservices.com 2204 clc.stackoverflow.com 2173
- userbinator 8y agoI'm not surprised. I remember reading before that Germany was one of the countries with the highest adblocker use.
- PhasmaFelis 8y agoTo think it only costs $100 and a few days' shipping time to get all the benefits of a software ad blocker than anyone can install for free in less than 60 seconds.
- zaarn 8y agoPi-Hole offers more than a simple software blocker, or rather, something a bit different. Everyone on my wifi or LAN benefits from adblocking. Even guests that are just there for the day. Devices that cannot run adblockers benefit. It doesn't require any installation at all. And if you bought a compatible raspi plus PSU for 100$ you go scammed pretty hard, I'd pay 40$, maybe 50$, for that combination tops.
- PhasmaFelis 8y ago> Devices that cannot run adblockers benefit. Adblockers have been available on the Android and iPhone app stores for a while now. > And if you bought a compatible raspi plus PSU for 100$ you go scammed pretty hard I'm quoting from the article, which admittedly uses Australian dollars. But I still don't see a need to pay any amount of money for the benefit of hypothetical visitors who already don't care enough to install a free adblocker on their phone. I'm sure there are valuable use cases for the Pi-Hole; in an small office environment, or if you fear some very specific malware, or if you really, really want a bulletproof way to block ads in free phone games. I object to the article making it sound like it's something everyone needs in their home, giving no coherent evidence and ignoring the real drawbacks. (The first thing I do when a site doesn't work is try disabling AdBlock Plus; even ignoring anti-adblockers, quite a few poorly-designed sites just break if an adblocker is running. A hardware adblocker that can't be locally or temporarily disabled with a few clicks is a bad idea.)
- zaarn 8y ago>Adblockers have been available on the Android and iPhone app stores for a while now. There are more devices than Android and iPhone, esp. some Android devices with higher lockdown. Additionally some of them either require Root or routing all your traffic through a VPN (either local or to some remote server) which costs battery and bandwidth. >But I still don't see a need to pay any amount of money for the benefit of hypothetical visitors who already don't care enough to install a free adblocker on their phone. You're not paying money for those visitors, you pay some cash if you need hardware to run a simple adblocker solution that protects all devices on your network instead of just the ones you can install software too. >I object to the article making it sound like it's something everyone needs in their home, giving no coherent evidence and ignoring the real drawbacks. Not quite, in your comment you object to the existence of a software based solution running on any hardware (though preferably on an RPi) over a software solution running in your browser. The Pi-hole isn't purely restricted to the RPi and can run on a VPS or old laptop you have lying around. Pi-hole can be easily temporarily disabled and I've done so to disable anti-adblock detectors in the past or debug some DNS issues. It's not hard. There is definitely some advantage to setting it up for a family, on top of the advantage of protecting visitors, it's set-and-forget; I haven't touched our local pi-hole installation in about two years. It's essentially maintenance free. I don't block so aggresively that all websites break, the only ones that break are cancer anyway and people begin to use them less so there is no point in giving these websites a free pass anyway. For anything more I still rely on uMatrix due to finer control. If you want to object to the average family having on of these you should consider formulating it other than "why buy hardware when I can install software?" because that's neither covering the argument not particularly convincing.
- myf01d 8y agowhat about path based blocking for https websites? this dns-based method isn't really effective unless for known ad and tracking domains, I guess most of the time you need to block a certain path and that cannot be known for the case of https except inside the browser itself after decrypting the TLS payload. Also this could break some websites and users don't even recognize this is due to pi-hole. This is why I believe that adblockers at the endpoint like ublock-origin are the most effective way to block ads.
- ohiovr 8y agoPi-Hole has dnsmasq built in so it is also handy for doing things like connecting to ssh servers in your network with your own hostnames instead of just ip addresses.
- b3lvedere 8y agoMy experiences using a Pi-Hole at home (Debian VM) have been very good. Recently i upgraded to version 4.0 (https://pi-hole.net/2018/08/06/pi-hole-v4-0-released-with-ftldns-improved-blocking-modes-regex-docker-and-more/ https://pi-hole.net/2018/08/06/pi-hole-v4-0-released-with-ft...) and it seems working perfectly fine. Great job Pi-Hole team! Thank you!
- j0hnml 8y agoIs there any reason you chose running on a VM as opposed to something like a RPi3?
- geerlingguy 8y agoMarginal speed gains (though Pi hole isn’t super resource-intensive so the speed up isn’t huge unless you’re piping through a ton of DNS traffic), and you don’t need a Pi at all :)
- crtasm 8y agoMine is on a Debian VM too, I already had a server to put it on and my RPI is busy running 4player super bomberman :-)
- BLKNSLVR 8y agoI only ever played 2-player super bomberman on the SNES, but it was once of the most fun games I've ever played. Now I've gotta make this possible for / with my kids!
- crtasm 8y agoBack in the 90s I read about this new HDTV thing they had in Japan and how they could play TEN player bomberman on it - mind blown. SNES bomberman 3 I believe actually supports five players (one on joypad port 1 and four more via multitap on port 2). Runs great on Retropie, my nephews love it.
- 8y ago
- vmp 8y agoI wrote a lightweight DNS proxy for this purpose in python+twisted and sqlite3: https://gitlab.com/Sharky/blocklist2bind/blob/master/twisted-dnsblocker.py https://gitlab.com/Sharky/blocklist2bind/blob/master/twisted... which also works really well on a RaspPi 3 with pypy3.
- a_imho 8y agoBlocking is good, obfuscation is better.
- r3vrse 8y ago> In other words my current smartphone will be unsafe for everyday use after September 2018, but it may have some life left in it by protecting its operating system with some network level security. I stopped paying attention when I read this. Pi-Hole is an ad blocker and it is fit for that purpose. No argument from me. However, to give this advice to people for whom device and network security is not a major or even minor concern is frankly dangerous. Buy an iPhone. Buy a Mac. Keep your Windows PCs updated. Get a mesh WiFi solution that takes care of firmware patches automatically. Run a browser-based blocker that updates in the background without interaction. These are the low-hanging fruit that should be done long before you are trying to set up what is essentially MITM-as-an-appliance without any paid support or guarantee. Who is this article actually helping?
- paulcarroty 8y ago> Buy an iPhone. Buy a Mac. Keep your Windows PCs updated. What?
- jacobush 8y agoAn iOS device tracks a lot of what you do, especially if you don't opt out of anything iCloud. But the bulk of the tracking is done by one "evil" corporation, who takes the majority of its money from selling devices. With a normal Android device, you are tracked every step of the way, by apps, by Google, by Samsung and their awful software quality or by random Chinese entities. If you don't spend a lot of time, an iOS device is the lesser evil when it comes to tracking. An iOS device with automatic app updates turned off, no iCloud, and where you say no to most apps asking for permissions on first run, is pretty locked down. There are downsides, of course. It's kind of sad that you can't buy a mobile device which is just a network node by default, not a spying machine by default.
- sgt 8y agoAgree with this. Android is unfortunately a bit of a disaster in terms of privacy and security. The easiest security advice you can give to say friends and family would be to just buy an iPhone. As for asking them to buy a Mac - I can list a few dozen reasons why that is also a good idea.
- robszumski 8y agoDoes anyone have experience with the optional network ad blocker built into the eero? I think it’s an additional charge so I haven’t tried it. Does it use this same rule set?
- paulcarroty 8y agohttps://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts and you don't need a device.
- badbug 8y agoWhere do I edit the hosts file on my iPhone? Or my Android device? Or my smartTV, etc, etc, etc
- hello_asdf 8y agoI put mine on router with dnsmasq.
- rndomsrmn 8y agoOr https://github.com/notracking/hosts-blocklists https://github.com/notracking/hosts-blocklists that uses a dnsmasq feature to block full domains.
- moltar 8y agoJust got one a month ago. Doesn’t work for YouTube ads, which was my primary use case. In Canada, we don’t have YouTube Red, and thus there’s no way to buy out of the ads. Also I loaded all block lists marked as safe. Yet many sites are broken. Now I’m contemplating as to how best to repurpose the Pi.
- crtasm 8y agoMake a Youtube-dl server? Or run kodi+YouTube and watch on your TV with no ads.
- technofiend 8y agoUse it to carry all your traffic to a US-based host via VPN and purchase YouTube Red with a US address? Hacky, I know.
- r3bl 8y agoYou'd have to be connected to the VPN at all times to use it. The minute you're not using it, all the Red features disappear, regardless if you have an active subscription or not[0]. So your option is to have an always-on VPN. If you're doing that from your phone, you might as well install NetGuard, which is a no-root open source adblocking solution that MitMs your connections by pretending to be a VPN, and is available on Google Play. Works with YouTube, and doesn't require monthly subscription. [0] Source: Activated the YouTube Red trial when I was on a travel to the US, and lost all the benefits the moment I landed home.
- greenshackle2 8y agoSince mid-June it's been renamed YouTube Premium and you can get it in Canada.
- moltar 8y agoSweet! Thank you for letting me know! Problem solved :D
- driverdan 8y ago
- obituary_latte 8y agoI love that pi-hole will even block commercials on “free” tv apps that run on fire/apple tv.
- mlevental 8y agoI bought a pi exactly for this and couldn't get the to work. it broke YouTube because the commercials wouldn't load. have you managed to get that to work?
- obituary_latte 8y agoSorry — didn’t try with YouTube — it was working with Crackle and if I remember correctly the AMC app. That’s odd though because I’m pretty certain it blocks the YT adds on my phone (unless that’s the Purify/1Blocker add block apps which it may be).
- mlevental 8y agoon appletv it does block ads but it also prevents some videos from playing
- pbhjpbhj 8y agoI tried pi-hole (a few months back on an rpi3) and am pretty sure it got hacked, making something like 100,000 DNS requests in a few minutes during a low use period. I'd guess that's some sort of advertising impressions hack. Unfortunately I didn't have time to sort the issue, so can't guarantee I didn't err. But I stopped using it; which was a shame as I really liked the device usage reporting in particular. Anyone else had similar? Make sure to check your stats.
- Majestic121 8y agoThis article might be of interest to you : https://docs.pi-hole.net/guides/vpn/overview/ https://docs.pi-hole.net/guides/vpn/overview/ It describes how your Pi-Hole can be used for DNS Amplification Attacks by attackers, and how to prevent it
- 24gttghh 8y agoIf the case is the pi-hole was an open resolver, then a simple firewall rule should have been enabled to block port 53 from the WAN...
- t3ra 8y agoI am actively using PiHole in my home network with over 8 devices doing around ~30k requests per day. Some highlights: * By a huge margin the nosiest device is my Android Phone. >40% traffic is coming from just my phone (which is crazy!) * I have 650,000+ in my domain blacklist and folks complaining about "it doesnt work on pihole" just have taken that tiny bit of error to unblock some domains like "ssl.googleanalytics.com" which break a lot apps. It took me about 1 day to see what isnt working (ex Facebook app break if graph.facebook.com is blocked) * On avg 28% of my requests are blocked and 42% are cached. I am quite sure generally my surfing experience is snappier -- Things like learn running PiHole : How prevalent tracking really is across the web. A lot of apps dont go "online" if google analytics is blocked (example Toggl) Manufacturers like Xiaomi are spamming the network with requests - mostly for notification spam How amazingly scalable, stable RPi+PiHole is - we ran a workshop with 150+ DHCP leases and nearly a few 100k DNS requests without a glitch. Pi didnt even heat up a bit SmartTV are freaking noisy. Samsung TV makes ~300 DNS requests in <5 min of startup. Literally every button press in the "smart home" is tracked
- luxpir 8y agoI wanted to say something positive too, after seeing how the thread went here. No issues from the non-technical users in the household, at all, really. The domains I've whitelisted are mainly one-offs - I haven't whitelisted GA as above and nothing has broken here. I've ended up using uMatrix and uBlock together on my personal machine as they don't interfere with each other and uBlock has an extra list or two that blocks even more tracking and ads - including all youtube ads. Which is just so satisfying. But other devices (of all kinds) run ad and tracker free, with a faster browsing experience to boot. So that's no ads on any devices on the network, all running on a pi that is also a media centre, NAS and IRC client. Takes minutes to set up and is regularly updated. I don't get what's not to like.
- iDemonix 8y ago> * By a huge margin the nosiest device is my Android Phone. >40% traffic is coming from just my phone (which is crazy!) I work for a small ISP-for-schools. We had an issue which eventually turned out to be related to a specific version of Snapchat on Android, when its connection back to Snapchat was blocked, it'd try and send a mixture of GET/POST at a rate of 1000s a minute. When you've got thousands of devices doing that, it's like an internal DDoS. We've had a few problems like this and it always appears to be Android apps...
- alexrsagen 8y agoThe page is very self-contradicting... It says in verbatim "However, I do have a problem with: Pop-up and pop-under ads that hi-jack my internet browsing experience". However, the site itself has a "subscribe" overlay that has to be removed with developer tools or manually blocked if uBlock Origin is enabled with annoyances filters.
- ziftface 8y agoI guess he made his point
- admax88q 8y agoIt really seems like the only reason I need this device is that most of my devices are not truly under my control. The fact that my phone does not have these features baked in and comes with apps that violate my privacy and serve me ads without regard for malware those ads may contain is because my phone doesn't truly obdy me first.
- mlinksva 8y agoDoes anyone use Pi-Hole for larger-than-home networks, e.g., for an office, cafe, school...? Also, it seems like Pi-Hole ought to be a router feature rather than requiring a separate device. Does any router vendor or router OS distro integrate Pi-Hole?
- witnessmenow 8y agoI have a relatively short video (~8 mins) explaining how pi-hole works and how to install it if anyone interested https://youtu.be/_rZhCLh3WyY https://youtu.be/_rZhCLh3WyY
- muxator 8y agoAlternative for those who run OpenWRT on their modem/router: you can opkg install adblock, and also get an easy web based administrator interface via LuCi.
- kevlar1818 8y agoIf you run OpenWRT/LEDE on your home router, you can just install this package: https://github.com/openwrt/packages/tree/master/net/adblock/files https://github.com/openwrt/packages/tree/master/net/adblock/...
- ocdtrekkie 8y agoFinally broke down, got out an old Pi I had in storage and set up a Pi-Hole last week. So far the experience has been pretty positive.
- expertentipp 8y agoInternet without ad and tracking blocker is unwatchable and unusable at this point. Occasionally I get taste of it while browsing on the iphone (unable to edit the hosts file) and it is a nightmare. Advertisers and tracking providers hijacked the web.
- ectospheno 8y agoiOS has several nice ad blockers and has for quite some time now.
- dingo_bat 8y agoWhat's the advantage over just using ublock everywhere? Why go to all this effort and include another point of failure in your network when you can just install an extension?
- vitaflo 8y agoThe advantage is for anything you can't install ublock on. It's program agnostic.
- class4behavior 8y agoPihole manages your hosts file which redirects domain names to a configured IP-address; a local one when the goal is blocking. It is a bit overhyped but useful when you understand what it's for. It uses the same lists as uBlock, but only the rules which filter the entire domains. Meaning, uBlock covers a lot more ground and preserves the operability of most websites. As such, just for browser activity it is a redundant measure. The difference is, for everything else it affects all your traffic; that is, Android or Windows apps, telemetry, bad content in HTML emails, etc. If you install it on a router, you can cover all your devices. That can immediately or later cause issues with websites and apps inhibiting usage when ads or trackers are blocked. So you need to be available for whitelisting.
- veritas3241 8y agoThere's a persistent bug with my Pi-Hole where every time it's active it causes my wife complains that several of the websites she wants to visit are unusable. :-D
- intopieces 8y agoIs this something I can put next to my parents’ router and not kill their internet experience? They like Facebook.
- eximius 8y agoI use wireguard with DNS routed to an `unbound` instance on the wireguard VPS. The VPS costs me $1/mo. The only problem I've gotten is when `unbound` crashes because it uses ~400MB of RAM to hold the blacklist and the little vps only has 256MB of RAM (and 1GB of swap)!
- randop 8y agoFor me i use http://www.ipcop.org/ http://www.ipcop.org/ then use the blacklist on http://www.shallalist.de/ http://www.shallalist.de/ Using this on an old laptop.
- kstenerud 8y agoI've added an LXC container builder for it: https://github.com/kstenerud/virtual-builders/tree/master/machine-builders/pi-hole https://github.com/kstenerud/virtual-builders/tree/master/ma...
- deleted 8y ago[deleted]
- adultSwim 8y agoI do not have a problem with internet advertising in general. I do.
- NoPicklez 8y agoQuad9 offers a similar type of network-side ad-blocker for free. https://www.quad9.net/ https://www.quad9.net/