5 ms·
An Exercise Program for the Fat Web
- Crinus 7y agoDoesn't DNS over HTTPS and HSTS bypass pihole? (isn't it funny how every single "modern web security" feature, from DNS over HTTPS, to HSTS even to HTTPS itself always ends up with someone giving up control to 3rd parties yet this is always dismissed and pushed through insane amounts of peer pressure - usually by people who have vested interests in those 3rd parties - because 'security'?)
- detaro 7y agoDNS over HTTPS against a server you can't choose would do so, yes.
- fenwick67 7y agoYou could still shut down the initial DNS query for the dns-over-https provider and make it unreachable
- NetBeck 7y agoSome people refuse devices that do not accept DHCP assigned DNS servers.[1] [1] https://mailarchive.ietf.org/arch/msg/dnsop/WCVv57IizUSjNb2RQNP84fBclI0 https://mailarchive.ietf.org/arch/msg/dnsop/WCVv57IizUSjNb2R...
- tracker1 7y agoYou can also reroute port 53 traffic not from your internal dns server to your dns server...
- thedanbob 7y agoSo does simply using a different DNS server than the network supplies, unless you’re blocking port 53.
- kasey_junk 7y agoMy network is setup so local dns goes to the pi-hole which uses dns over https.
- bryanlarsen 7y agoSwitching to Firefox costs $0 and works on every network, not just your home net.
- throwmeback 7y agoIt's also hella buggy on macOS for me, which is irritating - my browser is the only thing I need to work 100% of the time. As much as I'd like to reduce Google's browser monopoly, I consciously choose to make this one exception.
- mooreds 7y agoHave you tried brave? Not sure if it has feature parity, but it is a new take on a chromium based browser.
- throwmeback 7y agoI did for some months, but the synchronisation isn't working yet for iOS. I'll gladly switch to it once they have it working.
- lucideer 7y agoDefine hella buggy? What's not working for you? (apart from the obvious recent f-up with the addon signing obviously, which—while glaring—was at least a one-off)
- robin_reala 7y agoAny particular bugs that are annoying you? The main one for most people seems to be excessive battery consumption on retina displays, which is being worked on (requires switching the renderer interface over to Core Animation, so is understandably taking a while). Apart from that I can only think of minor annoyances compared to some of the problems with Chrome like major memory consumption and the gradual strangling of personal privacy extensions.
- throwmeback 7y ago
- fenwick67 7y ago> Eye/o GmbH owns AdBlock and uBlock Wow, I didn't realize the same company that owns Adblock also owns uBlock.org (but not ublock origin)
- Theodores 7y agoI am interested in what happens when you get to a website that insists you turn off your ad blocker. What happens with Pi Hole? Also I would prefer to just run Privoxy as I have Ubuntu running and can just use that instead of some extra gadget. What happens with Privoxy if you are getting a turn off ad blocker message? Currently I use 'cat block' or the 'EFF' blocker, depending on what computer I am on, those give you an option to turn off your ad blocker which I find myself doing from time to time, it would be nice to have this option with Privoxy.
- theandrewbailey 7y agoYou can disable blocking temporarily (a few seconds to a few minutes) in the PiHole dashboard.
- jdietrich 7y agoThat sounds rather inconvenient compared to the two-click option in uBlock Origin.
- kasey_junk 7y agoits literally a 2 click option in pi-hole.
- tech4all 7y agoIt is actually incredibly easy if you use a password manager and have your local pi-hole credentials all saved. Maybe 4 clicks and I've disabled both my pi-holes (primary and backup) for 15 minutes. I've been running 2 pi-holes for almost a year. I've been surprised at how well they work and how few sites have issues. I've only encountered 2 problems: 1) Administering Google Ads... Of course it needs to be disabled. 2) Oddly enough Lowes website has very odd online ordering issues unless you disable the pi-holes.
- nkrisc 7y agoIt's maybe a few extra seconds.
- 7y ago
- zeveb 7y ago> It's kind of scary how powerful DNS can be, isn't it? And that, I think, is why we see a push for DNS-over-HTTPS and other things: because eventually Google (and other device manufacturers) will only use the network-provided DNS servers to find their DNS servers. And of course your device will only use Google's servers, for your security of course. You might think that sounds crazy, but we've already seen it come to pass: Android apps will now ignore owner-supplied root certs. This means that the device owner cannot inspect HTTPS traffic sent by his own device. The endgame is that we're not really owners of our own computing devices, but simply renters of media-consumption appliances.
- nixpulvis 7y agoIf I don't own my technology, I sadly own very little. It makes me really sad.
- eswat 7y agoPi-Hole is a great tool, just make sure to be exhaustive in your testing to see if it will break any services you depend on. When I unboxed my old Kindle one day I couldn’t get syncing to work and had no idea why for several days until I tried adding a pass-through filter for Amazon in Pi-Hole, which was the culprit.