23 ms·
Setting Up a Pi Hole Made My Home Network Faster
- djpilot 7y agoPi holes were already discussed extensively and at length a few months ago: https://news.ycombinator.com/item?id=18075159 https://news.ycombinator.com/item?id=18075159 https://www.troyhunt.com/mmm-pi-hole/ https://www.troyhunt.com/mmm-pi-hole/
- paavoova 7y agoAnd the conclusion was, at least for me, is that this doesn't require Pi Hole if your router software supports ad-blocking (OpenWRT, pfSense do), and that DNS-level blocking cannot replace wide-spectrum content type blocking such as in browser addons like uMatrix.
- stevewillows 7y agoWith Asus routers that can run Merlin [1], AMTM [2] is a nice little suite for adblocking. All you need is a USB formatted to EXT4 and you're good to go. [1] https://asuswrt.lostrealm.ca/ https://asuswrt.lostrealm.ca/ [2] https://github.com/decoderman/amtm https://github.com/decoderman/amtm
- ris 7y agoYet more hardware junking up the world for people who can't configure software. Got to wonder how rigorously people who install umpteen of these sorts of devices around their home maintain them.
- llukas 7y agoPlease share how do you configure standard android phone or smart devices (TV) phoning home.
- snazz 7y agoMaybe the GP means that you can run a DNS server on your router? Most people own very locked-down consumer routers, however, so this is rarely an option. Speaking of that, does anyone know of a router that lets you run any operating system (I was thinking OpenBSD) but with better energy usage than a full computer?
- jinnko 7y agoHave a look at OpenWRT
- mutt2016 7y agoMofirouter ships with it from factory..
- agurk 7y agoBy router I assume you mean WiFi AP, firewall and router. I run pfSense on an Intel box I got from AliExpress (i5-6200U, 8GB ram) as my firewall and use its 6x Ethernet ports for basic routing. Despite having a decently powered spec, in operation it takes 8-9W power. Searching AliExpress for pfSense returns lots of options, many will have lower consumption. For WiFi I have a tp-link AP (EAP-225) that takes about 3W. This is a bit more than an all-in-one consumer unit (the one I replaced was a couple of watts), but I'm very happy with its power consumption.
- nocturnial 7y agoYou can try openwrt: https://openwrt.org/ https://openwrt.org/ You can install several packages including adblock and cryptdns-proxy. Here's a list of supported routers: https://openwrt.org/toh/start https://openwrt.org/toh/start
- gordo4 7y agoPCEngines APU
- mkup 7y agoI have a positive experience with Turris Omnia. It doesn't run OpenBSD, but it runs OpenWRT-based TurrisOS, and also supports LXC containers (generic ARM-based Linux distros like Debian, Ubuntu etc). By the way, it's possible to install PiHole inside such a container. Besides that, it has builtin WiFi (2.4 and 5 GHz radios) and a plenty of hardware resources (2 Gb RAM, powerful CPU).
- xfitm3 7y agoSpammy blog.
- LeoPanthera 7y agoIf your home router is a pfSense device, you can do this in-router, by installing pfBlockerNG. No Pi necessary.
- miketery 7y agoHave recommended model?
- godzillabrennus 7y agoBuild your own router with an appliance you can find on eBay. Lots sold on their for you to load your own pfsense install on. The parent company (Netgate) has price their hardware higher than I believe the market supports.
- LeoPanthera 7y agoI installed it on a PC Engines APU2.
- maayank 7y agoI really like their hardware. Recently upgraded it to a wireless AP and it's the best AP I ever had, including Google's OnHub
- leonroy 7y agoDid you have any performance issues after enabling pfBlockerNG? I have a pretty hefty pfSense box but running pfBlockerNG caused all sorts of weird slow downs of DNS resolution through the pfSense DNS Resolver for all clients.
- LeoPanthera 7y agoI do not! And I'm not running on anything particularly high-spec either.
- mmastrac 7y agoAny pointers on a good "low risk" pi-hole list that trades off maintenance effort versus blocking? I'm OK if it doesn't block everything - just want it to run in the background with zero effort.
- snazz 7y agoThe default ones feel that way to me. I use a Pi-hole equivalent plus a client side adblocker (uBlock Origin), request/domain blacklist manager (uMatrix), and JavaScript blocker (NoScript) on Firefox. The Pi-hole-like-thing needs to be disabled or something needs to be whitelisted at most once every couple months. I have to enable JS or third-party content much more often than that, but the trade off to protect my privacy is worth it.
- jakear 7y agoWhy do you use both NoScript and uMatrix? It was my understanding that uMatrix would block JS, but thinking about it now maybe it doesn’t block JS embedded in HTML? Is that the idea?
- gorhill 7y agoBoth uBlock Origin and uMatrix are able to prevent execution of inline JavaScript.
- snazz 7y agoI could probably consolidate, but I’ve grown accustomed to the defaults and interfaces in both and the combo works well enough as it is. There’s no better reason than simply my personal idiosyncrasies.
- ehsankia 7y agoIdk about Pi-hole, but I use AdvancedTomato on my router, which has built-in ad-block, and I've run into many issues with it. Sometimes, I really do want to click that ad on Google search, or I'm looking at some "deal site" which routes URLs through an advertiser, and there's no way for me to open that link. It gets really annoying. Not only that, blocking the request is nothing like a real ad-blocker removing the element, most of the time it still leaves boxes with errors in the middle of the content you're browsing.
- 171243 7y agoI was thinking of a device similar to a pi-hole for blocking TV commercials. It plugs into your TV's HDMI port and somehow as soon as a commercial starts it switches to playing some relaxing music or a low key picture slide show. Even just switching to a blank screen would be better than the commercials yelling at me. Not really sure if it is feasible because it would have to have the smarts to distinguish between the actual tv show and a commercial but I'd play good money for something like this. And for bonus there would be some running metrics, just like how those water fountains that say something like "saved 3432 plastic bottles from entering the environment," this would say "saved you for seeing 242 hours of commercials"
- killlameme99 7y agoI know laziness sells, but really is it so bad to just click the mute button and turn on some music? I rarely watch TV these days but when I do I often sit with a different form of entertainment (music player, laptop, handheld video game system) and just switch to that during commercials. To me the real issue with commercials isn't the fact that they're selling me something, it's the fact that they're interrupting my entertainment. That will happen regardless of whatever pops up on my screen. In saying all that, I do like the concept. Perhaps video taping a show and removing the ads afterwards would have the optimal effect? Just googling around I seem to find some video taping software already has this feature, not sure how well it all works though.
- monocasa 7y agoUnless I'm watching the muted commercials intently (which sort of defeats the purpose), I'll commonly miss the beginning of whatever show I was watching when it comes back from the commercial break. I'd really appreciate some automation to handle that for me.
- codetrotter 7y ago> Not really sure if it is feasible because it would have to have the smarts to distinguish between the actual tv show and a commercial but I'd play good money for something like this. If you live in the US, and broadcasts are delivered to you with IPTV, then reading about SCTE-35 might be of interest. https://en.wikipedia.org/wiki/SCTE-35 https://en.wikipedia.org/wiki/SCTE-35 Though I don’t know if these control messages are actually included in the video stream that is broadcast to the viewers, so it might be a dead end, but I think I read that at least some channels do include them in the broadcast stream. Might be worth looking into.
- blunte 7y agoI setup a rpi+pihole a month ago after reading an HN post, and I was amazed at how much faster most browsing was (especially on phones). I've only had a couple of things that didn't work because of the pihole, and honestly I found it faster to just make a phone be a 4g hotspot, connect my computer to that hotspot, get past the "hump", then switch back to my home network. It's not ideal, but it doesn't happen often.
- rbritton 7y agoI’ve had a similar experience, but it’s been around a year for me. I very rarely have to whitelist anything anymore. Beyond the obvious, one use I’ve had for it is when traveling in an RV and using a bandwidth-limited connection. Not eating up quota with all of the ad assets is very nice.
- jachee 7y agoPro-tip for an easier work-around the next time you hit a "hump": http://pi.hole/admin/ http://pi.hole/admin/ and use the "Disable for 30 seconds" option. :)
- starky 7y agoEven easier, you can create a bookmark in your web browser to disable it for a specific amount of time. https://www.reddit.com/r/pihole/comments/81z8jp/temporarily_disable_pihole_using_a_bookmarked_url/ https://www.reddit.com/r/pihole/comments/81z8jp/temporarily_...
- ngngngng 7y agoI've found a few apps that are able to get around this. The Youtube app on my phone is still able to load ads even when I use this method, and the Hulu app on my Playstation. Does anyone know how they're able to do this and if there is a solution?
- vpx 7y agoYou can't block YouTube ads by blocking DNS queries, since they are served from the YouTube domain itself. Basically, you can't block them without blocking the entire site.
- Moru 7y agoThere are other ways of blocking YouTube ads that works great but needs an install on each device.
- fedorareis 7y agoHow does uBlock do it then? I always assumed it did blocking based on domain.
- smilespray 7y agoIt has access to and parses the web page and can as such do advanced pattern matching in various ways. Domain, subdirectory, file, you name it. It can also hide HTML elements known to contain ads in order to collapse the blank areas where the ads used to be.
- crispinb 7y agoTempting because playing with Raspberry Pis is always quite fun. I'm not sure why - I can spend an hour doing something on a Pi that would make me groan to bother with otherwise. But a question for anyone who's done this Presumably most of the computing devices in your home make their way onto other networks from time to time. So you need a per-device solution to the ad infestation in any case. What's the point of adding a house-wide one? This is the consideration that's stopped me doing this so far - the adblocker I currently use is going to have to remain in place regardless, so what would a Pi Hole add (other than a pleasurable hour or so toying around)? [Edit: I don't have a smart tv, google home or similar net-connected but unhackable device]
- patrickdavey 7y agoNever let the good be the enemy of the perfect :) adding a PiHole will work for all your devices at home, tablets that don't usually leave the house etc. It doesn't stop you from running adblockers on devices in addition. As it takes about 10 mins to setup it's totally worth trying out.
- crispinb 7y agoI'm tempted, but can you think of anything it adds over device-installed solutions (which all my devices have, and will keep because they all travel)?
- joshvm 7y agoBecuase the blocking happens at the router (ish) level, it should also prevent adverts inside applications where you can't run a blocker, eg mobile apps. That doesn't solve the problem when you're out of the house although you can set up your devices to use your pi as a dns server when you're away from home. https://docs.pi-hole.net/guides/vpn/overview/ https://docs.pi-hole.net/guides/vpn/overview/
- crispinb 7y agoFair point as applied to browser-based adblockers. In my case I use Adguard, which works as a proxy on a PC/Mac, or a VPN on android. AFAIK Pi Hole would just be duplicating what I already have. Worth considering though when my current Adguard licences expire.
- mutt2016 7y agoHow a single rasp pi made my browsing experience terrible and slowed page loads. I turned off my pi hole. Personal anecdote only
- BenjiWiebe 7y agoYou must have had something misconfigured. Loading less stuff won't slow down browsing.
- seasalim 7y agoHad a spare Rpi sitting around and just set this up... it's working like a charm so far. Before this, I was feeling annoyed that even though I was subscribing and paying sites like WPo, I was still getting blocked from reading articles if an ad-blocker was on. With the Pi-hole that problem is solved, and browsing seems faster as a bonus as well.
- marcrosoft 7y agoSo I did this too. The downside is that if that pihole server goes down your entire network loses DNS access.
- tbyehl 7y agoDo wish they'd come up with an HA strategy. I run mine on old, low-wattage PC hardware that cost me about $30 all-in and boots in 20 seconds, so at least I'm not at the mercy of unpredictable mSD cards or an ESXi server that takes 10 minutes to start launching VMs after a power outage.
- detaro 7y agoIf I remember correctly, client OSes that know about multiple DNS servers will try the other if one fails, so just have two and announce both through DHCP?
- marcrosoft 7y agoI'm not positive but I believe it works by blocking the request which means an alternative route would be used and defeat the purpose. Edit: if that's not the case I still think applications round robin also defeating the purpose.
- detaro 7y agoI meant two PiHole-based servers. But a "blocked request" is an answer, and would likely not trigger a request to a different server, but I wouldn't rely on that being entirely leak-free.
- marcrosoft 7y agoI didn't think of having two. That's probably a good enough solution if you have two servers.
- 7y ago
- remote_phone 7y agoI bought a raspberry pi and ran pi hole but it keeps turning off for some reason. I guess I got a faulty raspberry pi? But when it does go down all my browsing dies because no dns requests could be processed. So I went with running it in a docket container on my nas instead.
- givinguflac 7y agoI would try a different power supply and outlet, if you haven’t already. Personally I use Diversion, which does more than pi-hope and is available for Asus-WRT Merlin firmware. Http://Diversion.ch
- voltagex_ 7y agoTry a different power adapter. The Pi3b+ is better than older models, but can still pull 2A at 5V.
- TheRealPomax 7y agoAnd remember that the pi power supplies are actually 5.1V, not 5V - you can get way with 5V as long as your supply is a 3+A supply, so that at top draw, your supply isn't going to deliver a lower voltage while it tries to max out the amps. (it's why my raspi's are all on 5V/3.5A supplies instead)
- voltagex_ 7y agoFor anyone else reading this, the Amazon Echo (Dot) power supplies are among the best I've tested. I'd also recommend a USB tester like the RuiDeng UM24, especially if you use a lot of SBCs or USB powered devices.
- darkmighty 7y agoApart from the power supply mentioned, is your temperature fine?
- lostlogin 7y ago
- xrisk 7y agoFor some reason, the Google Play Store stops working when I try to route my DNS traffic through OvenVPN to a Pi-Hole running on my droplet. Anybody here know why?
- dillutedfixer 7y agoHonest question - with such an emphasis and desire for security in the home network, how is the Alexa justified?
- FridgeSeal 7y ago"I implemented ad blocking and privacy measure in my home network and then undid my efforts by installing commercial spyware inside my network"
- TheRealPomax 7y agoWhat's the speed cap, though? Doesn't it turn whatever your connection speed is into "only as much as the pi can do"?
- wrboyce 7y agoNo, the Pi is only serving DNS and acting as an empty endpoint which ads are redirected to.
- otherdave 7y agoThe Pi isn't the router, it's just a DNS server / lookup. No data actually flows through it.
- JudgeWapner 7y agono, it doesn't do deep packet inspection. it just blocks DNS queries. So when your webpage says "show the java script ad at xxx.yyy" the DNS is sent to PiHole, which sees xxx.yyy as a spam domain, then instead of resolving that IP, it says "oh, you want to load spam.js from xxx.yyy? Here it is: {}". It actually makes pages run faster.
- adrianmonk 7y agoI've never used it myself (so all this is theoretical), but it appears that the only traffic you route through it is DNS. So all your bulk data transfer (HTTP, etc.) would go at the normal speeds. DNS itself doesn't involve a lot of work for the server to do. It's a pretty simple protocol / system that doesn't require powerful hardware. So assuming their blacklisting implementation doesn't bog things down, it should be able to serve DNS requests at the normal speeds. In some cases, it could actually speed up DNS because you'd have a local caching server which you might not otherwise have.
- arduinomancer 7y agoDoes using a Pi hole break any websites? I'm curious if any websites use JS to check if the ad was successfully loaded.
- jachee 7y agoIt does. But not many. Most notably CVS.com who serve some of their JS from holed sites. Fortunately working around is as easy as going to http://pi.hole/admin http://pi.hole/admin, hitting "disable for 30 seconds" and reloading. My experience since installing has been overwhelmingly positive. [Edit: pi.hole is http not https.]
- drexlspivey 7y agoYou can ad your own adlists by editing /etc/pihole/adlists.list. There are a lot of curated lists with domains circulating the internet for example https://v.firebog.net/hosts/ https://v.firebog.net/hosts/. I found that with the default lists it runs very smoothly but if you start adding a lot of domains it might break some sites. If you break a site you can always whitelist it or disable blocking for a while through the web interface.
- city41 7y agoSome sites detect you are ad blocking. Most just say “please disable your ad blocker” but some sites refuse to show content.
- tgbugs 7y agoI run ublock, privacy badger, and noscript in firefox in addition to my pihole. Unlike the local in browser solutions pihole will sometimes cause extremely long hangs on poorly engineered sites that are hard to distinguish from network connectivity issues (because in a sense they are intentional network connectivity issues). For example, the chrome web store hangs because google essentially requires you to allow ssl.google-analytics.com and has a multi-minute timeout set (just checked and it is 140 seconds when trying to retrieve ga.js). After a while you learn to recognize when a site is having pihole issues and you go check the log.
- lostlogin 7y ago
- kingo55 7y agoWorth exploring DNSCryptProxy as an alternative, too. In addition to acting like pi hole and blocking certain hostnames, it allows you to encrypt your DNS lookups for anything forwarded to DoH or DNS Crypt supported services.
- hyperdunc 7y agoPi-hole supports dnscrypt-proxy. You can set them both up on the same Pi but listening on different ports, then tell Pi-hole to use dnscrypt-proxy on localhost as its DNS provider.
- dmourati 7y agoI skimmed the blog and setup pi-hole at home. So far so good. I was mildly irritated at the Docker fanboy tone but that's my own bias.
- spaceisballer 7y agoSo what’s the advantage of running the docket setup of Pi hole versus the normal Pi install?
- rahimnathwani 7y agoIf you already have a PC running 24x7, you don't need a separate device to run pi-hole.
- spaceisballer 7y agoOk thanks, that makes sense. I don’t leave my PCs on so I’ll keep my little Pi running.
- ezoe 7y agoWhy Raspberry Pi? That will be a serious bottle neck. Does he use 56Kbps modem?
- DenseComet 7y agoNot all traffic flows through the Raspberry Pi, just DNS. DNS doesn't need much bandwidth.
- lostlogin 7y agoPi model B+. Current load 0.04, 0.05, memory 20%. Blocklist of 1 million and doing DHCP and a few other small tasks. Small network of about 10 clients.
- userbinator 7y agoThis is essentially a better-managed, centralised equivalent to the long-standing practice of using the HOSTS file to block unwanted sites at the DNS level. Unfortunately it seems there's now a desire for browsers (and soon, maybe other applications/systems will follow) to make DNS requests inside HTTPS tunnels (DoH), but maybe that'll just encourage more the use of MITM proxies which have almost become a taboo amongst the force of "HTTPS everything" security-authoritarianism. Web security these days may be just as much focused on securing the profits of the advertising and tracking companies as it is against malware and actual user hostilities...
- donmcronald 7y agoYeah. HTTPS everywhere and DoH have always seemed like part of a 5 year plan to kill ad blocking. Once the ad networks can use HTTPS + DoH + ESNI + CDN we’re screwed. Application level DoH is just nasty. I also think it’ll encourage consolidation onto the existing major providers because everyone is going to want to be on an unblock-able IP block.
- wurst_case 7y agoI'm sorry and I know these kinds of posts are sometimes discouraged here on HN but do you have a eli5 for that or possibly some reading I could check out. Why would https everywhere allow advertisers to enhance their targeting?
- endymi0n 7y agoI see less of a conspiracy there and more a classic tragedy of the commons. If you make it harder for malicious parties to intercept, read and modify your requests, you automatically make it harder for security research and any beneficial purposes as well.
- TeMPOraL 7y agoOr simply, past some point, security and usability are enemies. It seems to be impossible in practice to tell whether a thing is being done by a fully-aware user, by a confused user, by user under duress, or by malware impersonating the user - so the standard approach to security is to simply kill off any feature that could even remotely be misused. Which essentially means any and all features that are not under full control of the service provider. One day soon someone will figure out that the right way to deliver any and all content is through an end-to-end, cryptographically secure server -> HTTPS -> NIC -> HDCP -> screen pipe. And then we'll all have TVs instead of PCs, but at least they'll be secure™.
- llao 7y agoPlease add "Pi-Hole" to the title, this is just the umpteenth post about that and the title is clickbait.
- dang 7y agoOk. Here are some of the others: https://hn.algolia.com/?query=pi%20hole%20points%3E3&sort=byDate&dateRange=all&type=story&storyText=false&prefix=false&page=0 https://hn.algolia.com/?query=pi%20hole%20points%3E3&sort=by...
- jedisct1 7y agoYou don't need a Raspberry Pi for this. Just install dnscrypt-proxy.
- jeena 7y agoWhat I'm still missing is something which could detect and remove native advertising. I'm paying $10 to youtube every month specifically to get rid of ads, but then basically every content creator has native advertising baked in which youtube doesn't remove. It would be great if the creators needed to mark the start and end of native ads so that youtube could just jump over them for me.
- paulcarroty 7y agohttps://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts Solve all my problems with ads and also effective against social, porn and gaming addiction.
- maayank 7y agoNot trying to be inflammatory, but to educate myself. “Like any other project I run everything in a Docker container, and this project should be no different“ Why? I assume they don’t maintain their own image for home use
- josteink 7y agoNot the same, but I run such thing inside manually crafted LXC-containers. It helps isolation, and doesn’t pollute the LXC-host itself. When I want to remove/replace something deleting the container is guaranteed to do a 100% cleanup. It also helps migrating apps/services across hosts/servers. Now I don’t do that very often, but the few times I do, it’s a godsend.
- bbcfake 7y agoWhy hn shadow ban users ? Quite lame.
- martin_a 7y agoAh, another "I managed to set up a Pi-Hole"-post. Love it. Maybe need a dozen more of those with some clickbaity titles...
- mattlondon 7y agoSo genuine question, with PiHole how do you temporarily disable it for one website/app? With browser-based tools it is super easy to turn these things off when it breaks things (e.g. flight booking sites often fail miserably with an ad/tracker blocker I've found). If you come across a website that breaks with PiHole do you have to change your DNS settings to get around it?
- martin_a 7y agoYou can login to the Pi-hole Admin Console and choose to disable the blocking functionality. Either permanently until reactivation or for a defined timespan (10 or 30 seconds, 5 minutes, user-defined span). But you can't disable it on a per website base as it's working on DNS level.
- crtasm 7y agoIt is often pretty easy to look at the blocked domains log and spot what might need whitelisting, which is a single click away.
- PappaPatat 7y agoHaving a large(ish) family using the wifi with plenty of devices, I too suffer from this problem. So my current solution is..: install the application called 1.1.1.1 (from Cloudflare) and activate it when you (think you) need to access something that is (potentially) blocked by our pi-hole. Not perfect, but easier than explaining the pi-hole admin interface and consequences of their actions.
- anonu 7y agoYou can also just change your computer or routers DNS settings as such: https://news.ycombinator.com/item?id=18788410 https://news.ycombinator.com/item?id=18788410 This approach has way less overhead than pihole... But now someone else knows what you're browsing. Edit: the top comment specifies the hostname incorrectly. It should be: dns.adguard.com (not .org)
- ralphc 7y agoDoes using this to maximum effect mean I have to change the DNS for every device on my network or is there a single change I can make to my router?