4 ms·
What’s wrong with pi-hole?
by ryall 7y ago
What’s wrong with pi-hole?
- bertil 7y agoNot the OC, but I use uBlock, not pi-hole simply because: - hardware, and I’m lazy (admittedly, that doesn’t really qualify as a good reason); - I browse on mobile, at work, from cafés, etc. I like the idea of having a device that handles my connection everywhere and my mobile and laptop are always “on wifi” with that device. I’d love to have a centralised solution to use the dodgy wifi connection at airports, for instance.
- vector_spaces 7y agoYou can set up pi-hole + a VPN on a cloud provider to solve the mobile problem. I did that, and it's great, but I do recognize that it has greater time demands (setting up the server, hardening it, setting up the CA, generating keys, ongoing maintenance, etc) and expense. Here's a dated but reasonable overview of the process from Digital Ocean: https://www.digitalocean.com/community/tutorials/how-to-block-advertisements-at-the-dns-level-using-pi-hole-and-openvpn-on-ubuntu-16-04 https://www.digitalocean.com/community/tutorials/how-to-bloc...
- close04 7y agoUnfortunately DNS based ad-blocking solutions are nowhere near as effective and convenient as an extension like uBO. Even if you have a publicly available DNS based service they will tend to be more lax in order to not break sites which lets many ads through. I use a combination of PiHole, Firefox+uBO, and VPN + FW rules to stay as much away from ads as possible even when browsing mobile. uBO is the single most convenient and effective measure out of all of them.
- chimen 7y agoOr you can use a DNS server that handles that for you, like dnsadblock.com
- ignoramous 7y agoNice. nextdns.io [0] is another alternative, which may not remain free forever. dns.adguard.com [1] is decent for a free offering, though offers no custom rules. [0] https://news.ycombinator.com/item?id=20012687 https://news.ycombinator.com/item?id=20012687 [1] https://news.ycombinator.com/item?id=18788410 https://news.ycombinator.com/item?id=18788410
- dspillett 7y ago> hardware It doesn't have to be real hardware: you can run pihole in a VM (KVM, Hyper-V, etc) on your local machine. It'll eat a bit of RAM of course, but it doesn't need a huge amount to serve one user. This doesn't solve the setup time of course, and trouble-shooting time if something goes wrong. For mobile I run OpenVPN at home: all my traffic when on on my phone provider's network or public/guest wifi goes down that including DNS request going to my pihole instance. This isn't perfect of course: there is still some setup and maintenance involved, and some networks block or significantly throttle VPN traffic (throttling can be worked around by running the VPN on port TCP443 if it is done by simple port based rules but that may mean having a spare IPv4 address to hand).
- kevin_thibedeau 7y agoThis is a really obtuse way to run a proxy server.
- dspillett 7y agoMy pihole isn't running on a "client" machine, though it is running on a VM on the home router/server just to keep it entirely separate to aid maintenance. A container would do the job too. I was just pointing out that the OP wouldn't need new hardware to set up pihole. And in my case the VPN is not just for accessing my ad-/malware- blocking DNS resolver, but also for accessing other local resources and for general paranoia (nothing goes over the mobile network or public/guest WiFi unencrypted). Useful extra feature: because payment processors think I'm at home I'm bothered less by extra identity verification steps than I would be if my source address and therefore derived location changed regularly. DNS traffic going through the VPN stops the network intercepting and forcing it through their resolver anyway (I'm looking at you, Sky) and means that I don't have to make my DNS resolver visible to the unwashed masses. So I'm not just being obtuse. IMO, anyway.
- zenexer 7y agoAn important nitpick for those who are unaware: hopefully you use uBlock Origin, not uBlock. uBlock is owned by AdBlock and allows "Acceptable Ads".[1] [1]: https://en.wikipedia.org/wiki/UBlock_Origin#uBlock https://en.wikipedia.org/wiki/UBlock_Origin#uBlock
- dredmorbius 7y agoBelt and suspenders. Pi-Hole (or equivalents, I use the OpenWRT Adblock package on my router) work through domain and host-based blocking, which is powerful, but not exclusive, and carries side-effects. As a bonus, if your local resolver (which is what Pi-Hole is) serves your local LAN or WiFi network, ALL devices are automatically protected, at least while they're on that network (and are configured to use that resolver). uBlock Origin works based on domain-based blocks, but also other heuristics, and (where the capability exists) can block specific elements within Web pages. Generally, Pi-Hole or other resolver-based DNS blocklists: - Covers all local devices and applications. - Its configuration can be automatically configured via your network's DHCP server. - It covers all applications. - It works only for devices while they're using that network or DNS resolver. Generally uBlock Origin or other extension-based adblockers: - Cover only the application for which they're installed. - Offer more extensive blocking capabilities. - Work regardless of network you're on or when roaming in mobile state. Where possible, I use both. For devices and apps in which uBlock Origin (or equivalent) isn't available, I rely on DNS-based blockers. When I'm mobile, unfortunately, I get ads, and really, really, really, really hate them.
- nonbirithm 7y agoIt only works on a domain/host level of blocking, but not content blocking. Pi-hole can't do anything about blocking ads in the Android YouTube app, for example, because Google serves the ads from the same domain as the video content.