6 ms·
Seemingly every other week for months now a Pihole post makes the front page on HN. Every time I wonder why. IMO, it's just a DNS black hole with a slick inter
by nominated1 7y ago
Seemingly every other week for months now a Pihole post makes the front page on HN. Every time I wonder why. IMO, it's just a DNS black hole with a slick interface.
Before adblockers came along I had a script that updated my hosts file. I then moved to a DNS black hole but it’s been more than a decade since I’ve used either solution.
Do you people have that many hostile IoT / Smart thingies connected to your networks? Are you just unwilling to pay for the ad-free versions of apps. Are you using apps/services on these devices that don’t offer an ad-free option, if so why? I’m genuinely curious.
- Nextgrid 7y ago> Are you just unwilling to pay for the ad-free versions of apps. Note that paying and hiding ads doesn’t mean the app stops talking to the ad server. I had one app which pinged the Google Ads server even after paying (not going to name & shame as it’s a small independent developer so I’m leaning towards it being a legitimate bug). Oh and don’t forget analytics which paying doesn’t work against at all.
- kxrm 7y ago> Do you people have that many hostile IoT / Smart thingies My primary reason for running PiHole? Two Roku devices that cannot help but call home. It doesn't take "many" to make it annoying and unwanted.
- buro9 7y ago> IMO, it's just a DNS black hole with a slick interface This is why it gets to the front page. It's a DNS black hole with a slick interface. You run it and it does great by itself, manages the updates, and when it does do something you don't want (or vice versa) there's this really slick interface for figuring it out and correcting it. We underestimate how much slick interfaces are worth, especially when they make a chore that was almost entirely CLI driven and making it a non-chore for a bigger audience.
- asutekku 7y agoThis is a thing a lot of engineers don’t seem to get. Slick interface is the most important thing for public, no one wants to use terminal or advanced settings to actually do anything related to your product.
- nominated1 7y agoMy comment also states that since adblockers have come along a DNS solution seems a bit archaic. Adblockers are even more slick and user friendly so your reply doesn’t at all answer, why? Why move back to a less than solution? Lack of device control, unknown alternatives, unwillingness to just say no (for whatever reason… not criticizing here) seems to be the answer. Unfortunately, as ignoramous states there are techniques that will render DNS blacklisting useless if they want to.
- ignoramous 7y agoIf these increase in popularity [0], I'm pretty sure DoH will be the goto workaround for web apps and native apps, alike, which would be unfortunate because DNS based ad-blocking is all encompassing and takes very little effort to setup [1]. That makes me wonder why DoH was even conceived, if not for the benefit of ad-networks [2]? Thinking along similar lines, can't help but wonder if cert-pinning does more harm than good. -- [0] Folks have been doing this since atleast 2002 http://sam.zoy.org/writings/internet/doubleclick.html http://sam.zoy.org/writings/internet/doubleclick.html [1] https://adguard.com/en/blog/adguard-dns-announcement.html https://adguard.com/en/blog/adguard-dns-announcement.html [2] OpenDNS founder, davidu, has been crying foul about it too https://news.ycombinator.com/item?id=18257318 https://news.ycombinator.com/item?id=18257318
- monochromatic 7y agoProbably an ignorant question, but is there a way of disabling DoH at the firewall level?
- ignoramous 7y agoI don't see how DoH can be filtered at the firewall at request-level, since it looks like regular HTTPS traffic. Of course, MITMing HTTPS and then blocking particular DoH reqs and letting rest through would work, but apps that pin certificates might make MITMing an uncomfortable ordeal. Blocking a DoH provider altogether might not be feasible.
- jcastro 7y agoMy block rate is about _23%_. I pay for most web services I use, things have just gotten worse over time.
- eugeniub 7y ago> Are you using apps/services on these devices that don’t offer an ad-free option, if so why? Maybe the HN crowd avoids Instagram, Snapchat, and Facebook but most people don't, and can't unless they want to socially cut themselves off from parts of their social circles.
- pimeys 7y agoI use Pi-Hole for my home network and for my Android phone. Here's a screenshot of the current blocking situation from the phone: https://i.imgur.com/lTsZFhE.png https://i.imgur.com/lTsZFhE.png Almost 60%... I don't install many apps, I use Firefox with Ublock Origin. Most of the blocked requests are to Google or Facebook. At home I have it network-wide, and typically the block percentage stays under 10%. Until my partner opens his Windows 10 laptop, then the block graph goes up. Also my television talks to advertiser trackers (LG), which I can easily block from Pi-Hole. Why it's better than just a hosts file? One is I can easily whitelist/blacklist domains from the UI or I can just disable all blocklists if I need for any reason. I also like the statistics it gives me.
- ElCapitanMarkla 7y agoThe stats are fantastic I've picked up a few things that were making a crazy amount of requests. I don't know what Alexa is up to but over 1000 requests to device-metrics-us.amazon.com blocked each day
- slg 7y agoSlack is just ICQ with a slick interface. Dropbox is just rsync with a slick interface. Sometimes a slick interface is the most important feature of a product.
- the-dude 7y agoThe infamous Dropbox comment. I have tried the very same concept but embedded in a WiFi router many years ago ( https://wijvrij.nl https://wijvrij.nl, Dutch ). Apparently, this was not the right product-market fit. The PiHole is.
- JustSomeNobody 7y agoIt's about being in control, not ads. My network belongs to me. I get to say what data leaves my network. I get to choose who I support by leaving ads on. I get to choose who gets blacklisted because they take advantage.
- mikestew 7y agoIMO, it's just a DNS black hole with a slick interface. And something, something some rsync and ftp and you've got Dropbox. Yes, Pi-Hole is just dnsmasq with a pretty face, which is precisely why I use it. $50 for a Pi starter kit, and as soon as it hits your mailbox, you are about 20 minutes away from living the #adfreelife (and most of that 20 minutes will be redirecting your network after install. Where the hell are the docs for this router?). Sometimes I'm content to manually tweak JSON files all evening. And sometimes I just want to plug it in and pretty much works out of the box. Ad filtering on my network falls into the unsexy latter bucket of "just give me something that requires a minimum of yak shaving". Are you using apps/services on these devices that don’t offer an ad-free option Yes, the NYT as one example. The app still has ads. I continue to pay for the NYT to support good journalism. I don't get to pick both, so I choose to continue to pay. A device in my house went nuts and decided it needed to ping an NTP server 1K a night. Not anymore. In the end, I kind of get the impression you're spending more mental energy on arguments against, rather than ask yourself why someone might find it useful. I could come up with quite a list of reasons with just casual thought.
- nominated1 7y ago> A device in my house went nuts and decided it needed to ping an NTP server 1K a night. Not anymore. Wait, Pi-hole was your solution here? > In the end, I kind of get the impression you're spending more mental energy on arguments against, rather than ask yourself why someone might find it useful. I’m asking because I believe there are better ways. I could be called out for baiting or pushing a “the only way to win is not to play” for IoT and creepy apps/services agenda. Yet, NYT, FB and many others can still be viewed and signed into with a mobile browser. The experience may not be as nice but it still works and sends the right message to these corps. When creepy app/device/service is the only option I recoil and reassess. Besides, DNS blacklisting isn’t perfect and requires a fair amount of tweaking depending on how many thingies you’re using it with. Any compromise you make for one affects all others. I think we have the same goal of “having your cake and eating it too” just different methods. Either way, we’re both expending constant energy and compromising.
- paavoova 7y ago> $50 for a Pi starter kit And $35 for an OpenWRT router that does the same thing and also offers a web interface. Why pay more for a second standalone device?
- sumanthn 7y agoIt's so ridiculous because instead of wasting money buying unnecessary hardware people could just use already existing DNS servers that do the same thing. I block ads in my home because it's just a nicer web experience for everyone. Plus when I play games on my phone I don't get a barrage of ads every time I die. https://adguard.com/en/adguard-dns/overview.html https://adguard.com/en/adguard-dns/overview.html
- FredFS456 7y agoPihole is much more configurable: you can whitelist or blacklist domains with ease. However, Pihole can also be run on existing hardware like a home server, if you don't want a standalone pi.
- leetbulb 7y agoI have three machines on my network that are used for web browsing, all running uBlock and Ghostery. Two phones that aren't used for much internet-wise. A couple other devices such as a HTPC. I don't use Pihole, but I do use something similar for pfSense. I rarely mindlessly-browse the internet and I don't have any IoT junk. That said, my stats for 30 days: List Blocked ------------------------- pfB_IP1 35834 pfB_IP2 17606 pfB_IP3 150789 DNSBL_Malware 4 DNSBL_Ads 832479 DNSBL_Trackers 26085 Note: The top three are various IP blacklists (99% of blocked is ingress). The bottom three are DNS blacklists. It blows my mind every time I look at these stats and see how much they've increased... The data these companies would otherwise have on me. The data these companies have on everyone else. How much has actually gone through / missed / not blocked and rendered any of these efforts meaningless. At the end of the day, I don't really care, but it's all pretty neat!