23 ms·
Mmm, Pi-hole
- shmageggy 8y ago2663 requests over 17 minutes? Is there a Poe's law for the web?
- tomrod 8y agoThis is excessive. Amazingly so. I don't mind an ad or two. I don't want you siphoning my network and computational resources without compensation.
- daemin 8y agoI think the news sites are thinking the same thing. "I don't want you to use my network and computational resources (to read the news) without compensation (watching our ads/mining our coin/etc)"
- isserson 8y agoIn that case, these news businesses should not be publishing content on the World Wide Web. Users pay for devices, electricity, and monthly network connection, These publishers seem to be stuck in the last epoch. A website is not a finished product like a book or newspaper, it is publicly-accessible data. Users can scrape, restyle, delete, and add content _at will_ whenever they choose to download this content. So the ideology of capital, which destroyed community morals, is now having it's own tawdry ethics trashed. It's not news that the news is failing. This Author Wrote 7 Reasons Why You Can't Make 20th Century Business Web-Scale.
- SketchySeaBeast 8y agoSo what's the impetus for the news business to be available online? If the world wide web should be a free love utopia of data slurping why would these agencies, who have been built on the assumption that the creation and presentation of their data has an inherent worth? How do they get remunerated for their efforts? Or do they just never try to take advantage of this new epoch and die off, leaving us with a billion half-assed citizen journalists?
- krageon 8y agoI would pay for a source of journalism that had any actual effort put in it and wasn't blatantly and hilariously wrong almost all of the time. Sadly news agencies don't fit that bill at all.
- SketchySeaBeast 8y agoSo do you/would you pay for something like the New York times?
- malnourish 8y agoRead reuters, you don't have to pay for it.
- michaelmrose 8y agoI see nothing wrong with them charging money for their work they just can't depend on being able to exercise absolute control over the presentation because instead of being dumb data to be displayed on a remote device its code to be run on the end users device. You can't separate all the interesting aspects of this distinction and ignore the ones you don't like.
- paulcole 8y agoYou are being compensated. You can visit their website and read their content. Feel you're not being compensated enough? Stop visiting that site.
- jrace 8y agoYou are being compensated...but you are not being informed for what. As an example, lets say you borrow my truck. You compensate me for the use of my truck to move some boxes in town. But then you use my truck to tow a trailer across the country. That is more wear and tear on the vehicle. And then you take my personal information that is on my vehicle registration with my home address and sell that to an ad company. Finally you return my truck with all sorts of junk that was collected while the truck was being used.
- paulcole 8y agoExcept it is nothing like that.
- jrace 8y agoWhen you go to a website are your informed how much bandwdith will be ad only? How about what is done with your personal information? When you visit a website are you shown which tracking cookies will be left behind? You cannot stop visiting the site, once you have visited the ads have been loaded, the cookies have been dropped and your info has been mined.
- deleted 8y ago[deleted]
- josefresco 8y ago> And yes, I'll chat to her about the Fox News situation as well! Highlight of the article right here.
- jwilk 8y agoHopefully he told her beforehand he's going to spy on her…
- jumbopapa 8y agoI don't really see why he had to make mention of it.
- jonnycoder 8y agoExactly, heaven forbid we read different new sources to view different biases and takes on stories.
- robin_reala 8y agoHighlight in terms of sketchiness. I maintain our home network, but I certainly don’t spy on the sites my partner chooses to visit. Or post them on a high traffic blog.
- avenius 8y agoIt's about time this became a public discussion. Websites have become so horribly bloated, while most discussions seem to revolve around whether ads are acceptable or not.
- theandrewbailey 8y agoTo be fair, ads are the reason websites are bloated. I don't mind websites loading 50 MB if I'm in awe of the amazing multimedia presentation it's giving me. 50 MB of ads just... isn't.
- lbriner 8y agoThat's not always true. Check out the new GMail, my new corporate account has no ads but it still weighs in at 25MB (well 28MB now - still asyncing stuff!) for the inbox. In this case, the largest resources are Javascript and CSS (yes 1.2MB CSS files!). The weird thing is that it appears to be making requests with different cache-busting strings and getting resources that are the same size. (32MB now, I haven't done anything on it since starting this post)
- drb91 8y ago> Check out the new GMail, my new corporate account has no ads but it still weighs in at 25MB (well 28MB now - still asyncing stuff!) for the inbox. The new gmail is the slowest web app I have ever used. It's gotten so bad I've started managing my email on my relatively snappy inbox iOS client. It wouldn't be so bad if they didn't load so much crap, like the gchat functionality nobody has used since 2008.
- 0x8BADF00D 8y agoAgreed 100%. Just getting it to load takes forever, and Google Calendar sometimes never renders for me (on latest Chrome for OSX-1).
- mrob 8y agoThe old HTML only version still works. I just refreshed mine and got 19.11 KB transfered with cache disabled. (about half that with cache)
- lousken 8y agoWith disabled js dailymail loads 603(6.8MB) files 590 of which are images.
- bArray 8y agoI run uBlock Origin and noscript - even then I'm amazed with how much guff the UK Daily Mail website loads. From their perspective - you would think they would want to reduce the bandwidth to the servers as much as possible...?
- lousken 8y agoI run ublock origin and umatrix. And actually they do kinda care - I've tested their site on Chromium with no addons or blocking and noticed they lazy load most of those images (it loads "only" ~130images) and about 400requests in total (I only opted out from advertising using their GDPR dialog). If I opt in, it constantly pulls data ~6requests/second.
- r3bl 8y agoOff-topic, but that Vollkron font definitely styles 1s very weirdly. I thought it said I.I.I.I instead of 1.1.1.1 until I copied the text and pasted it somewhere else.
- another-cuppa 8y agoIt does say I.I.I.I. Awful font.
- callahad 8y agoThat's a common, traditional form for non-lining numerals (https://en.wikipedia.org/wiki/Text_figures https://en.wikipedia.org/wiki/Text_figures) Turns out, Al Gore doesn't like it, either: https://www.typotheque.com/blog/gores_choice https://www.typotheque.com/blog/gores_choice
- paavoova 8y agouBlock Origin allows you to block remote fonts and use system fonts instead. You can selectively enable them on a per-domain basis, and, for cases like this, have them blocked them by default. With remote fonts enabled on https://www.troyhunt.com/mmm-pi-hole/ https://www.troyhunt.com/mmm-pi-hole/ 24 requests 3.12 MB / 3.06 MB transferred And with remote fonts blocked: 20 requests 2.96 MB / 2.90 MB transferred It's not just ads you have to worry about.
- pbhjpbhj 8y agoFWIW, https://www.fontsquirrel.com/fonts/vollkorn https://www.fontsquirrel.com/fonts/vollkorn, shows they have a choice of styles for numerals. But the half height I appears to be the default.
- galadran 8y ago> Do you use a popular browser extension? How confident are you that the creator wouldn’t accept a $10k offer to hand it over only to have it then go rogue on you? What makes the Pi-Hole organization any more trustworthy? (and the software stack it all depends on) Personally, I'm inclined to trust them both and hope that the long arm of the GDPR will be effective. Optimistic, I know.
- travisp 8y agoIn this case it just acts as a DNS resolver. That's potentially risky when resources don't use SSL, but far less than a browser extension that can change a page in place, inject JavaScript, and record keystrokes on all pages.
- cremp 8y ago> resources don't use SSL Huh? DNS is hit even if the site is SSL. Unless the site has HSTS, and you've got to the site before; DNS poisoning is very much doable.
- filleokus 8y agoHow would the attacker do anything useful with a SSL connection attempt? They can either send the real certificate, and then not be able to decrypt the data, or send a self-signed cert which the OS/browser wouldn't trust? Are you thinking of some downgrade attack vector?
- emilecantin 8y agoYes, but the hijacker will still need to present a valid cert for that domain, which is much harder.
- msmith 8y agoSince Pi-Hole is a DNS server running on a separate machine, it just doesn’t have the same level of access as browser extension would. Even if it was rogue, the worst it could do is share the list of domains that you visit, and possibly hijack your HTTP (but not HTTPS) sessions.
- philg_jr 8y agoPi-hole is cool, but only works on your home network unless you use a VPN to connect back home and funnel all traffic over the connection. I'll continue putting my trust in uBlock Origin on FF for now, until I hear about any malicious PRs that get merged in /shrug/
- chupasaurus 8y agoYou can wind up a Linux VDS with dnsmasq and blacklist of domains, then use it on any device everywhere.
- ricketycricket 8y agoIf you trust your ability to secure a publicly-accessible DNS server. Pretty attractive target. Also, you can't usually specify DNS servers on cellular connections. The VPN setup would address that.
- drb91 8y ago> Also, you can't usually specify DNS servers on cellular connections. From what I understand this is only iOS.
- chupasaurus 8y agoAs a subscriber to Debian Security mail list from 2013 I'd got 2 emails on vulnerabilities in dnsmasq. I don't think anyone should trust cellular connections at all for many reasons. Especially because my country (Russia) is the only one in Europe which has an office of CEIEC (chinese surveillance gov company) which as of now makes Orwell's tales come true in Xinjang.
- deleted 8y ago[deleted]
- detaro 8y agoother recent pi-hole discussions: https://news.ycombinator.com/item?id=17696397 https://news.ycombinator.com/item?id=17696397 https://news.ycombinator.com/item?id=15608052 https://news.ycombinator.com/item?id=15608052
- WorkLifeBalance 8y agoSomeone on here recently recommended uMatrix for this purpose and I find that a nice trade-off between usability and request blocking. It's an extension but given it's less opaque than a generic ad-blocker I feel more in control and that it's less likely to go 'rogue' like adblockers do.
- AdmiralAsshat 8y agoLongtime uMatrix user here. The most frustrating thing about UM (which is the same problem I had with NoScript back in the day) is that some scripts call other scripts. So, particularly when I'm trying to play an embedded video served by another site served through a CDN, the process for getting the damn video to play is something like: Click video -> Open uMatrix -> whitelist some scripts -> reload -> whitelist more scripts being loaded by the first batch of scripts -> reload -> whitelist some XHR references called by new scripts -> reload -> finally whitelist the actual media being served.
- interfixus 8y agoYes, a bit bothersome at times. But if I take the trouble to finetune worthwhile sites I run into, and make the settings permanent, life does get markedly easier after a while. I rarely see an ad. I didn't see Troy's responsible sponsor message either. I should have and would have if he had chosen to display the thing without the need for scripting. So I don't feel hugely guilty.
- egeozcan 8y agoI have uMatrix and uBlock. In my case it was uBlock blocking the ad, not uMatrix... or maybe I had whitelisted it before? Not sure. edit: Okay, it's not blocked by default with uMatrix: https://i.imgur.com/B97lf35.png https://i.imgur.com/B97lf35.png
- gorhill 8y agouBO can block with pattern-matching URLs of network requests and additionally cosmetic filtering (hide DOM elements), while uMatrix works strictly with hostname of network requests and types of resources.
- user812 8y agoPi-Hole is beautiful and open-source. As long as it doesn't get too popular, tech savvy people can continue to enjoy network wide content blocking. Consider supporting them (but not too much ;): https://www.patreon.com/pihole https://www.patreon.com/pihole
- Cthulhu_ 8y agoWhy the "not too much"? IIRC Adblock was "compromised" in a way because it was more profitable for them to make deals with advertisers. If they made more money off of donations they wouldn't need to sell out.
- user812 8y agoWell, it was kind of humourous, based on the idea that ad-tech will switch to first-party proxies when too many people use Pi-Hole. But on a more serious note, it is simple products like AdGuard DNS which will probably make Ad-Tech sweat more, because it's so easy to use for average users. Adblock was compromised due to lack of integrity imho.
- move-on-by 8y agoPi-Hole is a bit different too in that they do not maintain any block lists. It does come pre-installed with several lists, but maintained by 3rd parties. Its also very easy to add items to the block lists or import new lists. I think having this separation of powers is wonderful and will aid in the protection of the project.
- windexh8er 8y agoI'm surprised this is the top slot right now. Troy, generally, puts out interesting info on security related news however this feels a bit minimal. Since the project has been around a number of years now, and it's not relegated to only a RPi I would have expected him to delve into things a bit more. Pi-hole will also break things. I think the common one I always heard from users on my network at home were that Google click-thrus for products always fail. But... Don't deploy it on an RPi. It's not worth the inconvenience of maintaining another entire device for a network service. There's an actively maintained container I'd recommend, or it's very easy to deploy as a VM. Troy also didn't hit on anything like DoH or DoT, surprisingly. Container link: https://hub.docker.com/r/pihole/pihole/ https://hub.docker.com/r/pihole/pihole/ Edit: word
- ryandrake 8y agoIt’s essentially dnsmasq which can be run directly on your wireless router if you are using custom firmware. No separate hw needed, no need to horse around with dockers or containers or any of that stuff. I’d guess a lot of people are already running dnsmasq for other purposes, so adding the blocklist and periodically updating it should be trivial.
- class4behavior 8y agoYeah, on openwrt you just install the adblock package https://github.com/openwrt/packages/tree/master/net/adblock/files#prerequisites https://github.com/openwrt/packages/tree/master/net/adblock/...
- HugoDaniel 8y agoWorks for most basic ads. Unfortunately basic ads are a thing of the 90's. Does not work for most common ads nowadays, as youtube et. al. run them from the same domain as other important parts for the app/site to run. For these you have to use a different approach, like running an extension in the browser to block them.
- user812 8y agoI see pi-hole as the first line of defense. With Pi-hole you can disable an adblocker when something doesn't work and still enjoy a fast web. But Pi-Hole still blocks the majority of ads, so it is possible to use it exclusively if you just want to make the web usable again. It's also great at home for family members who just want to surf faster and more private and secure but don't mind a couple of ads here and there. Especially when it comes to mobile Apps. I also want to highlight that most domains that are blocked are usually tracking services which makes Apps and Websites incredibly slow and increase traffic to a large extent. I think blocking those "services" is the true beauty of Pi-Hole. Ad-Tech is only the tip of the iceberg when it comes to commercialised tracking.
- Cthulhu_ 8y agoI'm amazed that something that (to me) as simple as an ad and analytics proxy running on the website domain isn't more of a thing yet. That will already circumvent a lot of ad blockers. Well initially anyway, the ones based on blocklists / patterns will probably be updated quickly.
- FroshKiller 8y agoYou really think anyone wants to maintain something like that, let alone subsidize the advertisers' bandwidth costs?
- woolvalley 8y agoIf it's their main source of income, they would. Maybe advertisers could offer better rates since you'd be reducing their costs.
- CraneWorm 8y ago> Somewhere in the middle is a responsible approach, for example the sponsorship banner you see at the top of this blog Uh, sorry, but uBlock Origin blocks it. Also, does anyone else finds themselves jumping straight into `reader view`?
- ObsoleteNerd 8y agoI had a little giggle at him mentioning his ad in an article about pi-holes, since I run a pi-hole and don't see the ad.
- floatboth 8y agoI've been using Privoxy. Killing two birds with one stone here: proxying access through a VPS to hide the home IP address && blocking ads. Apart from it occasionally blocking legitimate sites that begin with the word "ad" (something like, say, "adrian.blog.thing"), it works great. Because it's an HTTP proxy, it offers an interface for bypassing these unintended blocks.
- paulryanrogers 8y agoIf it's a dumb string-start check then that could be a lot of false positives. How often has it been wrong? I personally hate wondering why something's not working and having to go through every extension to debug my browsing session.
- floatboth 8y agoQuite rarely in practice.
- userbinator 8y agoProxomitron, which Privoxy was inspired by, has a few patches which make it filter HTTPS too (you need to install a certificate for MITM, obviously.) As more sites use HTTPS the ability to filter their content becomes more important too.
- jjnoakes 8y agoI hate ads as much as the next guy. This cat-and-mouse game has been going on for as long as I can remember. But I have to wonder why the ad networks don't require content creators to place some "ad libraries" into the web servers or CMS systems directly, so that the ads are served exactly the same way as the content (same domain, same pages, etc). That's my nightmare scenario. I figured it would have happened everywhere by now. I see it in a few places but it seems pretty rare. Is it the heterogeneous server-side environments that are slowing down this approach? If it ever takes off, what is the mouse to do?
- woolvalley 8y agoML that inspects content for ad-like behavior. Inspecting content of files or code and see if they match known adware, like an antivirus.
- pdimitar 8y agoWondered that many times myself. I see several reasons: (1) Their current tech still works on most users so it's not economically justified to invest several times more just to catch a few extra percent of the users (the tech-savvy) in their net. (2) They are not technically savvy enough to figure it out (thank Cthulhu if that's true!). (3) They do not want to pay for the extra bandwidth costs and to upgrade their servers. And they will have to do both because looking at any ad inspection article reveals that the ad/tracking bandwidth can be easily anywhere from 3x to 20x the bandwidth needed to serve the content itself. Furthermore, the ad/tracking tech uses elaborate scripting techniques to avoid part of the automated defenses of browsers or network devices. Running those scripts 24/7 increases your electricity bill significantly. Overall I believe it's a case of "we could probably do better but we get a hell of a deal for the minimal investment we made". Which is really good for us the techies -- because they leave us alone -- but seriously sucks for everybody else.
- ocdtrekkie 8y agoI set up a Pi-hole recently, and its been a good experience. Probably the one thing I always have difficulty with though is online streaming for TV channels. I tried whitelisting domains they used for their ads so that the shows would play, I ended up giving up after a half hour and pressing pause on the Pi-hole to watch.
- gnufied 8y agoSo I have tried using pi-hole in past and I think one of the problems is - some websites refusing to function if ads are blocked. IIRC - British Airways website uses some javascript that requires ad to be disabled for finishing checking in. It may have changed now but there are other websites too which may or may not work as expected. With browser extensions it is typically easy to disable the ad blocker one time and check if that fixes it. With pi-hole IIRC, it was much harder to do.
- paulcole 8y ago> some websites refusing to function if ads are blocked Don't visit those sites! They want your eyes and/or your money (if a subscription is an option) and you don't want to give it to them. Just stop going there! Edit: I don’t understand the downvotes. Sites aren’t obligated to give you something for nothing. Why does it feel like that’s the default view here?
- SippinLean 8y agobut there are other people that live in or visit my home. Maybe they want to visit those sites. I'd love a pi-hole like solution that was as easy to temporarily disable as a browser extension.
- PascLeRasc 8y agoLike some buttons? https://www.nickearl.net/2018/05/27/controlling-pi-hole-with-physical-buttons/ https://www.nickearl.net/2018/05/27/controlling-pi-hole-with...
- paulcole 8y agoIsn’t that the compromise of roommates or family? Not everyone gets what they want. Either they’ll move out, resent you, deal with it, or you’ll do what they want?
- woolvalley 8y agoThat is why I don't use pi-hole myself. I wish it would redirect to a different local webpage that allows you to click a button to temporarily unblock the domain for your ip, like the ublock blocked webpage that pops up sometimes: https://arstechnica.com/civis/viewtopic.php?f=3&t=1424503 https://arstechnica.com/civis/viewtopic.php?f=3&t=1424503 If it gets abused, then you can turn it off as an option.
- Cacti 8y agoShould be noted this is useful not just for ads, but also for devices phoning home and collecting metrics. Things like Win10, Netflix, smart TVs, etc. You don't have to use every blocklist on the planet if you don't want it to screw up normal web browsing.
- karrotwaltz 8y agoIt can be easy to bypass by having an IP / another DNS server hardcoded as a fallback. I would bet that some devices are already doing it.
- herf 8y agoAlso, you can get dnsmasq block lists from several places. https://pgl.yoyo.org/as/ https://pgl.yoyo.org/as/ has lots of formats.
- michaelbuckbee 8y agoThere's an interesting discussion happening in the comments where the fact that Troy's (very low key, topically relevant, non tracking, entirely text based) sponsorship banner is being blocked by some AdBlockers. I've found the same thing with Reddit ads (which also seem quite reasonable). I'm conflicted, I'd like for there to be some mechanism where reasonably implemented ad systems can flourish.
- koevet 8y agoBeen using the pi-hole for a couple of years now. Can only say good things about it, as it also disallow porn and the such (which is good with kids in the family). Sometime, it's convenient to be able to switch it off quickly (as someone mentioned, certain sites will mulfunction): so I created a simple Alexa task to turn Pi-hole on and off using voice, leveraging the pi-hole api.
- kpcyrd 8y agoSince he was pointing out scammers buying popular extensions: I would like to mention that this is a chrome specific problem. Something like this isn't common with firefox addons.
- yscik 8y agoI'd also recommend turning off auto-updates for extensions (which is possible in Firefox). You also get a page with pending and recent updates, complete with release notes if the addon author provides them.
- jniedrauer 8y agoIt's easier for me to replicate this functionality myself. I run unbound with a domain name blacklist. Same functionality, no need for additional hardware.
- pfschell 8y agoOne of the great things about using unbound is how easy it is to blacklist entire domains, without having to know the name of each subdomain ahead of time. I've been doing what pihole does for over ten years using pfSense. I'm up to 437,000 fully qualified domain names blocked, and over ten thousand domains blocked outright. It has been years since I've seen an ad.
- gorhill 8y ago> 82% reduction in the number of bytes transferred No doubt the reduction is important, however as per screenshots, the reported reduction should be considered somewhat inaccurate as he forgot to check "Disable cache" for the Pi-Hole version, while it is checked for the non-Pi-Hole version. We can see resources pulled from browser cache in the Pi-Hole version.
- kup0 8y agoWow, Daily Mail, 2663 requests and 57.6MB transferred... just for visiting the homepage. That is a ludicrous amount of data.
- efdee 8y agoI've tried using Pi-hole a few times in the past, but I always end up shutting it down again. It breaks too many things, and it doesn't block as many ads as a browser-based adblocker does. I wanted to believe, though.
- givinguflac 8y agoI run AB-solution.info on my Asus router for the same effect without the need for extra hardware besides a usb stuck. Highly recommend it.
- ObsoleteNerd 8y agoMy Pi-hole with updated block lists (blocking trackers as well as ads) sits at around 87.7% requests blocked, which is absolutely mind-blowingly ridiculous. I see absolutely no negative effects browsing like this. Everything I've come across still works fine. Even sites that detect uBlock Origin and tell me to disable it, will work with that disabled and Pi-hole still blocking the ads instead. I heavily believe we should be supporting creators, and go out of my way to support them in direct ways (Patreon, buying merch, direct donations, Twitch subs, etc), but I absolutely will not submit my family/kids to the mess that is online advertising these days. Ads that look like legitimate download buttons, or that run scripts to do cryptomining popunders, autoplay video ads with sound, etc etc. Modern online advertising companies are malicious entities that actively harm users, and I absolutely classify them as malware.
- slacka 8y ago> I heavily believe we should be supporting creators Agreed. Do you disable your pi-hole on sites like Reddit? They vet their ads so not have any of the malicious attributes that you described. All the larger newspagers like WaPo and NYT are also good about this too. I'm all for blocking intrusive or malicious ads. But quality content depends on ad revenue. The author dedicated an entire paragraph on donating to the pi-hole project, but no mention of supporting quality content with subscriptions or unblocking acceptable ads.
- Improvotter 8y ago> Agreed. Do you disable your pi-hole on sites like Reddit? They vet their ads so not have any of the malicious attributes that you described. I've still got ads blocked on reddit because they're so clickbaity as of late. They look like posts from subreddits I'm subscribed to and turn out to be an ad, no thank you.
- thieving_magpie 8y agoI hope more companies offer a paid version of their site that completely removes Advertisements. I cannot stand ads and won't use a site if I can see them. I'm not trying to be a bad guy though, I want to use those sites legitimately. My only option is to not visit them until they offer a compromise.
- sciurus 8y agoI don't use a browser extension, I use Firefox's built-in tracking protection. It is only enabled by default in private browsing mode, but it's easy to enable it for all your browsing. See https://support.mozilla.org/en-US/kb/tracking-protection https://support.mozilla.org/en-US/kb/tracking-protection I get 126 requests and 2.3 MB transferred on Daily Mail Australia, which seems comparable or better than what Troy saw with Pi-hole. See https://postimg.cc/3WYwZf3b https://postimg.cc/3WYwZf3b (Disclosure: I work for Mozilla.)
- lvh 8y agoThis is great: it has most of the benefits of an extension without the concern the extension gets compromised (you already have to trust your browser). The only downside is it doesn't address ads in things that aren't browsers, like mobile apps and the like. I wonder how long it's going to take for ads to be implemented server-side entirely.
- sciurus 8y agoTrue. For mobile browsing it works well as long as you use Firefox on your phone too, but it doesn't help for tracking and ads within apps. Pi-hole can help there, but only when you're connected to your home network.
- crtasm 8y agoOr when you run openvpn and pi-hole on a server somewhere and VPN your devices via it.
- deleted 8y ago[deleted]
- spurgu 8y agoIt's sad. I've so much wanted to go back to Firefox after 10 years on Chrome now but every time I give it a try it just doesn't do it for me. Mostly because I have quite specific habits and I don't remember off-hand what it was specifically the last time I tried it that made me give up, I should really do a write-up the next time I give it a go, as I love Firefox (what it stands for) but there's always that _something_ that makes me go back to Chrome after a week or so. Currently I'm exploring Vivaldi (based on Chromium, which has some awesome power user features).
- Leace 8y agoAre there similar projects but running on DNS-over-HTTPS(/TLS)? That way one could configure only the browser to use this and it would also work on phones that are using LTE (and not adblocking when using home Wi-Fi only) [0]. [0]: https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/android/ https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1...
- lvh 8y agoYou can run argo-tunnel/cloudflared on it and use that. You'd still be taking plain-old-DNS in, but the arguments in favor of DNS-over-HTTPS aren't as strong on a network you control. I don't think anyone has written custom DoH stuff you can easily run yourself yet.
- tammer 8y agoThere is clearly a mass market for preconfigured plug-&-play versions of this. Reminds me of the little bits they used to (probably still do) sell to go between landline phones & the jack to screen telemarketers.
- crtasm 8y agoYou have to change DNS on your router or on each device so I don't think it could be entirely plug and play? Preconfigured + some instructions seems doable.
- mirceal 8y agoI could definetly see a world where a device like this fronts your home router and is zero config. Maybe a “super” router?
- hello-w0r1d 8y agoI managed to get it running on a few Intel Edison's (no longer supported by Intel) that were lying around. It makes browsing a stress free experience. For anyone looking to get it running on an Edison, check this out https://hello-w0r1d.github.io/Installing-Pi-hole-on-Intel-Edison/ https://hello-w0r1d.github.io/Installing-Pi-hole-on-Intel-Ed...
- tpush 8y ago> [...] it's also the fact that running an ad blocker means giving a third party an enormous amount of power over your browser. That's why Safari's content blocker API is so great[0]. Creators of these extension have no access to my data and it's faster than normal extensions to boot. I'm using Wipr, which seems to work just as well as pi-hole on the example pages. Blocked his advert too, or at least I can't find it cough. [0] https://developer.apple.com/library/archive/documentation/General/Conceptual/ExtensibilityPG/ContentBlocker.html https://developer.apple.com/library/archive/documentation/Ge...
- jasonmp85 8y ago+1 for this. Reading his whole argument I was like "I don't think this applies to Safari Content Blockers"… There's no reason to have an ad blocker be anything other than local. Sure, it should be able to pull more rules, but during operation it should just match those rules. There's no need to have it be written in a language with e.g. XHR or whatnot.
- lose-frown-sans 8y agoSafari Content Blocker is pretty great but it's restricted to Safari only. So if you use Reeder, for example, to view articles then ads won't get blocked. As an additional system-wide layer, I subscribe to Peter Lowe's ad block list with Little Snitch. Now I can block all outbound requests to ad servers system-wide. As much as I like PiHole, I don't think it's a one-stop solution. It's generally easier to manage stuff locally on my system. I think the big advantage is for software that isn't as open (like iOS, tvOS, etc). I find that working in layers instead of trying to find a singular solution is easier to work with and provides more flexibility.
- MrEngineer13 8y agoThere are a couple of downsides to pi hole, anytime a page doesn't work I'll have to turn it off and check the page again. And you only block domains so if you want to block Google analytics you can but you can't access their website without turning it off
- greggeter 8y agoI've got mine running at Digital Ocean. Been using for four months. No downside.
- badbug 8y agoI tried pi-hole but my family couldn't make it work. Pihole blocks a lot of content they want to see, for example, email newsletters from our city gov. I understand why (privacy/tracking concerns) but it was just blocking too much and frustrating non-technical users in my house.
- chooseaname 8y agoI'm very curious why it would block city gov. I've been running it for over a year on my server and I have not heard a peep out of any family members complaining about not reaching anything.
- y4mi 8y agoA lot of newsletters use click tracking. These scripts are blocked with a full block list, making everything unusable. It's often affiliate stuff and the newsletters that do this stuff
- Mister_Snuggles 8y agoI found the same thing with emails sent from an airline. It was frustrating because I did actually want to follow the links in the emails as they were to do with a flight I was taking.
- HammerJack 8y agoThis project could be improved by using pi-hole and unbound (docker images available). Unbound is a caching recursive DNS server. In an article all about hijacking and trust of 3rd parties, I find it amusing the author saw fit to point to cloudflare's DNS.
- admax88q 8y agoWhy are our devices so far outside our own control that we need to run an additional device on our networks to help prevent them from making unwanted network requests? The whole approach of Pi-hole feels misguided. Blacklisting domains and hosts should be something easily done on my device locally. Then it comes with me when I visit friends or coffee shops, and it's easy to temporarily disable when it breaks something I'm trying to use. The fact that I can't do this on things like my phone really illustrates how little control we really have over our own computing devices.
- upofadown 8y agoYou can edit the hosts file on Android apparently and the Pi-hole is just a shared hosts file.
- biktor_gj 8y agoIt's a self-updating hosts file. If you only do it once in a month you'll start seeing ads again. Also you can edit the hosts file if you're rooted, but you definitely can't if you're running a stock unmodified ROM. If you're rooted and you only care about your Android phone, you can also install Adaway, which does pretty much the same thing without the whitelist capability (Get it on F-Droid), but if you have a number of devices to protect, and some of them are iOS devices, TVs or whatever that can't be rooted, jailbroken, or you don't have administrative privileges to, Pi-hole is a good choice (if you run pfSense at home you can also use pfBlockerNG, which is essentially the same thing too).
- moftz 8y agoHost file blocking on mobile devices produces some weird web browsing. I like using browser plugins because it gets rid of the whole chunk of html so it's like the ad was never there in the first place. On android, there are these huge blank spots you have to scroll past to keep reading. I still keep adaway on but I wish I could just use ublock origin with android's chrome.
- 8y ago
- eximius 8y ago1. Use Wireguard. 2. It has a DNS option[1]. Set it to your Wireguard server. 3. Setup unbound with a public ad domain list. (No link for this, Google is your friend and there are several different options with minor tradeoffs.) You're done. Now unless wireguard, a soon to be kernel project, or unbound injects malicious code, you're safe. Edit: oh and this also works on mobile [1] wg-quick man page - https://git.zx2c4.com/WireGuard/about/src/tools/man/wg-quick.8 https://git.zx2c4.com/WireGuard/about/src/tools/man/wg-quick...
- mitko 8y agoThis might be dumb question and me missing something: Is it technically possible for someone to set up a PiHole DNS service similar to how Google has 8.8.8.8 ? It would be much better user experience in my opinion to just set a different DNS than to have to setup a new machine on your network. Monetizing such service sounds tough as you have very minimal leverage over the users (by design!) but perhaps a Patreon/Foundation would be sustainable, similar to how Wikipedia is? Perhaps it could be bundled to a VPN service?
- robertely 8y agoYou really want someone you trust as a dns provider. It would be easy to exploit people and as you say it's basically impossible to monetize. There would be motivation to do so.
- TheBeardKing 8y agoDon't buy a raspberry pi just for this, chances are you have some old windows machine you can slap Ubuntu server on and set it up easily. That's what I did and I have very little Linux experience. My favorite thing about it is ad-blocking in mobile apps. I tried to use it with OpenVPN on my android phone for ad-blocking when I'm on cellular data, but the speed it was unbearable. I'm not sure if it was my crappy router or what, everything I read says that DNS routing should be neglibible to speed. The downside of pi-hole as opposed to a broswer extension is it's more difficult to allow things when needed, and whitelisting specific URLs can be difficult and slow to take effect.
- txcwpalpha 8y ago>Don't buy a raspberry pi just for this, chances are you have some old windows machine you can slap Ubuntu server on and set it up easily. That's what I did and I have very little Linux experience. But this would require having a full-blown PC running 24/7 and increasing your electricity costs by at least a few bucks a month. It would be much wiser to buy a $10 Pi Zero W and put Pi-Hole on it.
- woolvalley 8y agoI agree. The rpi will pay for itself in electricity cost savings fairly quickly. Also a reason to use a dedicated NAS appliance. Instead of the 60W minimum idle that desktops have, your at 1-10W idle with rpi zero and NAS appliances. Small laptops might have a more efficient idle although, so YMMV.
- DerfNet 8y agoHave had Pi-Hole running on an old 10" netbook for a little over a year now. Set it up just to play around with it, wound up being a perfect machine for it. Agree about ad-blocking on mobile. The killer feature with Pi-Hole is that you don't have to set anything up on each individual device; anything connected to your network suddenly has near flawless adblocking.
- eb00 8y agoPi-hole is so important to me that I am unwilling to use the web without it. I also will not use Microsoft Windows without it. The Mozilla DNS over HTTP project concerns me because of this. If DNS over HTTP becomes the default for most software then I will have a serious problem. Don't bother trying to tell me this will be optional. Absolutely nothing will make me trust you after the MR. Robot incident. I would cut off two fingers to use Safari on Linux and Windows.
- pdimitar 8y agoTo address your last: I am rebuilding my career lately and working towards an income where I have several thousand $ free every month so I can just buy a maxed out iMac Pro (~$13,500 I think) in 6-8 months and only use my PC for gaming. Already fully invested -- a MacBook Pro, an iPhone X, an iPad Pro. Only thing missing is a desktop machine. The fellow technical crowd in HN and Reddit loves to crap on Apple for "slowing down progress" but Safari is a very solid browser. Between a good ad blocker and reading mode, it actually gives you control and styles pages for... you know, reading. I really like Safari on all my devices because it allows me to consume content how I want and forces the websites to behave.
- c54 8y agoThe aria.microsoft.com domain is for analytics and client metrics for probably some microsoft produced app you’ve got
- deleted 8y ago[deleted]
- qrbLPHiKpiux 8y agoI've been running this for two years at home and at work and it's a God-send. I live the ability to block SM on my networks. FB can get to be such a distraction with employees.
- erikpukinskis 8y agoI fundamentally believe we have the right to transform content that comes to our devices. The idea that we have a moral duty to sit passively and absorb “experiences” in their intended form... I just don’t see how that works long term. It will just mean we get abused more and more and we have to take it. No, if you want my business you have to find a way into my consciousness that is compatible with the way I arrange information around me. That’s always been the deal. You can put a free circular in my mailbox and I am free to toss it without looking.
- a_imho 8y agoYou don't have to sit passively, you don't even have to block passively, consider using / contributing to services like AdNauseam or Noiszy.
- djhworld 8y agoI've been running pi-hole for over a year now, it just works. To make it easier to install and maintain I used this dockerised version https://hub.docker.com/r/pihole/pihole/ https://hub.docker.com/r/pihole/pihole/
- equasar 8y agoDoes this impact gaming latency performance? I play Quake Live so every ms is important for me.
- dylz 8y agoFor DNS? No - it makes no difference. DNS happens generally before you establish the connection.
- cmurf 8y agoIsn't this an admission the internet is not safe by default, and you need specialized knowledge and hardware to make the Internet safe(r)? Xfinity/Comcast hardware (cable and WiFi integrated) works with the Pi-hole how? I can't change the DNS addresses on Xfinity hardware. Ok so I have to buy my own router, in which case Xfinity blames all problems on running by own hardware. Another ISP with which I'm familiar, when running my own router and assigning DNS of my choosing (any, DNS Watch, Google, Cloudfare, OpenDNS, whatever), and the ISP actually redirects the DNS requests to their own DNS servers anyway. The only two ways I've found to get around this is: always on VPN, or DoH using Firefox+Cloudfare's test they're running. In this case, it's deceptive having a router that permits me to assign DNS addresses of my choosing. In either case it means distrusting ISP hardware, getting your own cable modem, or getting your own network router, and also a Pi-hole. It's esoteric knowledge. This is a remarkable industry failure.
- jrace 8y ago>Xfinity/Comcast hardware (cable and WiFi integrated) works with the Pi-hole how? Once the pihole has been setup and has an IP it becomes a DNS server, you just then tell your end devices to use the piholes ip address as the dns server. DNS requests either go where you want (static IP addressing) or where to the xfinity/Comcast (DHCP addressing). And no, the internet is not safe by default, by neither is the real world.
- rthomas6 8y agoDoes this work with Hulu and other things that try to prevent content loading if the ads are blocked?
- hectorm 8y agoI'm currently using my own solution [1] based on Knot Resolver, a shell script [2] that creates a blacklist from multiple sources and DNS over TLS to 1.1.1.1. It doesn't have a web interface as complete as Pi-hole, but it's very lightweight. To block ads when I'm not at home, I use WireGuard and pass DNS traffic through it. [1] https://github.com/hectorm/hblock-resolver https://github.com/hectorm/hblock-resolver [2] https://github.com/hectorm/hblock https://github.com/hectorm/hblock
- esaym 8y agoIf you have a router that already uses dnsmasq (or a simple hosts file) there is the dnsgate script that basically does the same thing: https://github.com/jakeogh/dnsgate https://github.com/jakeogh/dnsgate
- portaljacker 8y agoMy only issue is if I haven't been to a site in a while it makes an error showing page not found or something similar, then a reload fixes it. Otherwise, it's a godsend, especially on mobile. Though some...unscrupulous sites...I visit on mobile on some occasions still manage to redirect me to crazy shit. But I get way less adds pretending I have a virus.
- sbr464 8y agoIs it possible to chain DNS servers or do multiple lookups for one request? For example, a dns server that specializes in malware/antivirus checks, and one that blocks ads etc? I realize it's not performant, but it makes it hard to choose a dns provider when several have different features you like.
- user501254 8y agoPi-Hole is great! Around 30% of the traffic is blocked on all my devices. However, I would recommend adding a few more decent block lists to the default ones. Also updating these lists through a cron job on a more frequent basis is a good idea. Here's a script that you can use to setup pi-hole and additional block-lists: https://gist.github.com/user501254/1d4c8cb9f22fb51ae970f5fe0b1f50c4#file-configure-pihole-sh https://gist.github.com/user501254/1d4c8cb9f22fb51ae970f5fe0... Also make sure you are using 1.1.1.1 as your secondary DNS service. So this way in case your Pi-hole running RaspberryPi is down, your devices would be still be able to access the internet with some privacy.
- aphextron 8y agoFor anyone not interested in setting up pi-hole, having a blacklist host file is just as effective for your local machine [0]. I have that full list set as my /etc/hosts file on a Streisand server [1] and run all my devices through that with IPSEC VPN. It's a little more flexible than pi-hole since you can use your mobile devices over LTE with it. [0] https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts [1] https://github.com/StreisandEffect/streisand https://github.com/StreisandEffect/streisand
- michaelmrose 8y agoEdit: I'm an idiot didn't realize hacker news was actually paginated
- thsowers 8y agoIt isn't silently hidden at all, it's just on the second page because this story has many comments
- michaelmrose 8y agoThank you I feel silly I don't think I have ever even noticed the more button at the end.
- thsowers 8y agoNo worries, I think it only gets turned on (sometimes temporarily) for stories with high volume
- firefwing24 8y agoMeanwhile, I use both pi-hole + ublock origin for my browsing experience contrary to Troy's initial statement.
- apankrat 8y agoFor a hardware-free option let me plug my little weekend project called DNS Whisperer: https://github.com/apankrat/dnswhisperer https://github.com/apankrat/dnswhisperer It's been quietly spinning on our mail server for a couple of years and it works just as you'd expect it to. Block ratio is around 50%, with no notable effects on browsing experience. It also blocks various in-game ads on the iOS devices. I update the blacklist now and then, may be once every 4-5 months if that, but it's largely maintenance-free.
- michaelmrose 8y agoTroy's perspective seems to be lacking in several levels. The first thing is the nature of advertising. Advertising is an attack on the client to convince him to believe and ultimately to act in ways that could not be contrived through honest communication. It is an attempt to manipulate. Even his very benign banner represents an attempt to manipulate. A company buying such a banner wants an author to speak as he wouldn't naturally to give a degree of attention to the sponsors content that he wouldn't naturally inspiring us to give an unnatural degree of regard to the sponsor by implying that he does by plastering it on the top of his website. He expresses that blocking this attempt at manipulation is "unjust". Hi Troy as soon as your content leaves your website and runs on my computer there is no moral dimension to how I choose to display or not display elements. In the larger context he believes that the larger struggle is to find a way to fund creators through acceptable manipulation that merely tries to hack your brain but doesn't hack your computer or take up your whole screen. Maybe when there are a billion people out there blogging and the infrastructure to reach hundreds of thousands costs $20 per month nobody is going to pay you to blog. Most of the intellectual property out there isn't scarce and you are going to have to convince at least some of your readers that they ought to take the affirmative step of paying you to create because they value your work. If you can't you'll have to pay the $20 a month yourself and create in your spare time. Acceptable manipulation isn't an avenue I'm interested in supporting. Incidentally the pi-hole is an interesting but pretty bad solution. It is just technical enough to discourage 90% of people from ever trying it, worthless outside your home network, and requires even those interested to actually pull out their credit card and wait for shipping. This is enough to convince another 99% not to do it. If the website doesn't work with this dns based blocking OR you want to show ads to support that site this is in theory possible but only if you log in to another machine and edit its list over ssh? Whereas ublock origin can be installed by anyone in seconds for free, works everywhere, and can be selectively disabled on a particular site in 2 clicks. This is why almost nobody uses a home dns server but adblock extensions are becoming prevalent. Troy also tries to throw shade at extensions by suggesting that any particular extension could be bought by malware authors. This is a legit threat model we should all think more about but it applies to all software including the developers of pi-hole. "The last temptation is the greatest treason. To do the right deed for the wrong reason." -- T S Eliot Troy doesn't want us to avoid extensions so we don't get compromised he wants us not to run adblock extensions because they block his source of revenue.
- funkaster 8y agojust an FYI: you can also install this on your rpi if you're using archlinux: https://aur.archlinux.org/packages/pi-hole-server https://aur.archlinux.org/packages/pi-hole-server
- thecleaner 8y agoAre you using linux or did you get this running on a Mac ?
- geuis 8y agoI was experimenting with a somewhat similar idea a few years ago, https://github.com/geuis/lead-dns https://github.com/geuis/lead-dns. I took the most recent block lists that uBlock Origin was using at the time and filtered out all the css-based selectors to just get the domains and urls. Unfortunately it basically broke nearly every site that I went to, largely in part to blocking some top-tier domains from Google I think. You could run lead-dns locally on your machine, or on another machine on your network. I still think its a good approach and will be looking into Pi-hole since its a lot more developed than my early experiment.
- tareqak 8y ago1) What would be the quickest way to get a either a Pi-hole device or a router supporting that level of functionality (ad-blocking, and DNSCrypt) into the hands of normal consumers on a mass scale (e.g. completely non-technical users like my parents or grandparents)? 2) I know my next suggestion goes against net neutrality, but what would stop an ISP from doing something similar at the level of their router (or cluster of routers)? Update: Actually for 2), some places that provide Internet access to their users who aren't ISP customers (e.g. businesses, malls, municipalities, colleges/universities/schools) could roll this out as well citing bandwidth savings (therefore cost savings).
- deleted 8y ago[deleted]
- FooHentai 8y ago>What would be the quickest way to get a either a Pi-hole device or a router supporting that level of functionality (ad-blocking, and DNSCrypt) into the hands of normal consumers on a mass scale (e.g. completely non-technical users like my parents or grandparents)? Sell it as a turn-key appliance in a box with three ports: Network in, router in, and power. Operate as a transparent proxy, automatically update, web interface on the inside port only, etc etc. Biggest issue is ensuring it's got enough performance on both Ethernet ports to not bog down traffic.
- muppetman 8y agoYou don't have to run it on a Rasberry Pi! I have a little server under our stairs, with the Proxmox Hypervisor (KVM + LXC with a lovely GUI) on it. It's free and you can figure up VMs etc. PiHole is a LXC container. Seems silly to "waste" a bit of hardware when most people here will have access to some form of virtualisation. I've given it 256Mb of RAM and it runs fine.
- auslander 8y agouBlock Origin in medium mode, to block 3rd party scripts and frames, is much more effective, its not depending on any lists. I'd also neved point to Cloudflare resolver 1.1.1.1, and to Google's too. Use your VPN's dns or Quad9 9.9.9.9
- pdimitar 8y agoWhat is your recommendation based on? Why don't you trust Cloudflare but trust Quad9?
- tzs 8y ago> Somewhere in the middle is a responsible approach, for example the sponsorship banner you see at the top of this blog. Companies I choose to partner with get to appear there and they get themselves 140 characters and a link. That is all. No images. No video. No script. No HTML tags. No tracking. Even that is blocked by uBlock Origin with default settings. I wonder how it knows it is an ad?
- mmirate 8y agoThe last time I checked, the Raspberry Pi was considered unsuitable for use as an internet middlebox (or router) due to some kind of I/O bottleneck, having to do with (pardon the faded memory) its ethernet controller being attached to its USB controller instead of directly to whatever ARM's PCIe-analogue is, as well as its USB controller being a blob-encumbered Broadcom hunk-o'-jank. Has this changed recently? EDIT: Answer: probably not, but that's irrelevant because this Pi-hole appliance apparently just does DNS, not full traffic routing. Makes reasonable performance possible, at the cost of granularity.
- ydushyant 8y agoI tried this but it was very slow
- itsthejb 8y agoHonestly, considering how cheaply you can implement this (I resurrected an unused OrangePiZero), how easily it can be used (just plug it into a router LAN socket), it's crazy that the creators aren't actively looking to monetize this
- acranox 8y agoI run a dns server with BIND for my local network. Is there some equivalent way to get this functionality without using a Pi?
- mdonahoe 8y agoIf DNS blocking catches on, couldn’t ad networks just do DNS in the cloud and return IPs directly in the JavaScript?