4 ms·
I agree that blocking OCSP (Online Certificate Status Protocol) servers is a bad practice. The argument to block them is that they can be used for tracking purp
by lightswitch05 7y ago
I agree that blocking OCSP (Online Certificate Status Protocol) servers is a bad practice. The argument to block them is that they can be used for tracking purposes. OCSP stapling is a great way to use OCSP without the risk of tracking - but not everyone does it or supports it.
Anyways, I maintain an 'Ads & Tracking' blocklist that I believe is pretty reliable and you are welcome to give it a try if you like: https://www.github.developerdan.com/hosts/ https://www.github.developerdan.com/hosts/
I've been maintaining my list publicly for over a year, and I've got to say its not always clear what deserves to be blocked, what should be blocked but can't be due to broken functionality, and what is legitimate like the OCSP servers. Everyone has their own personal level of expected privacy vs functionality. Its impossible to make everyone happy. I just wanted to say that being a maintainer of these lists isn't always easy. The obvious example you provided with (ocsp.apple.com) isn't exactly obvious because it _could_ be used for tracking, and it certainly isn't need for functional reasons (although I would argue that it is needed for security reasons). Anyways, there is a lot of gray when it comes to blocking and you can't make everyone happy.
- drukenemo 7y agoSorry for my ignorance, but how could I load these into Pi-Hole?
- lightswitch05 7y agoNo problem, there is a FAQ on it: https://discourse.pi-hole.net/t/how-do-i-add-additional-block-lists-to-pi-hole/259/32 https://discourse.pi-hole.net/t/how-do-i-add-additional-bloc...