16 ms·
Remove almost all online garbage using Dnsmasq
- MegaDeKay 7y agoWhat would be the pro's and con's of using this vs. uBlock Origin and Privacy Badger, assuming somebody like me browsing on the desktop with Firefox?
- joaovictortr 7y agoIt can filter out DNS requests in the whole network for ads/tracker domains if used as the DNS resolver on your network, which would also include other devices (e.g. phones). Most smartphone apps perform a lot of tracker requests, which makes this approach very effective IMHO. What the network approach doesn't help with is when the ads are served from the same domain as the content. An extension like uBlock Origin solves this problem because it filters the content within the browser. So I think both approaches are necessary to filter out ads/trackers, and they also complement each other, one at the network level (dnsmasq or Pi-Hole) and the other at the browser/content level (uBlock Origin, PrivacyBadger).
- pfundstein 7y ago> phones Basically everything except computers. Smart TVs are another one.
- Arnavion 7y ago- It works for every application on your computer, not just web browsers that also support adblocking addons. Useful for applications with embedded web browsers (game clients, chat clients, etc). - The failure mode is to block rather than allow. Even with a browser with adblocking addons, the addon could accidentally be disabled or uninstalled (by you, by a browser bug, by a browser feature, etc), so you'll start seeing ads. If the DNS server gets disabled you won't be able to resolve anything, let alone see ads. (I used to do a home-made version of this, but resolving to a local gifserv so that I didn't have to see "page could not load" errors from ad spaces. But recently I got a pfsense router so I've switched to pfblockerng instead.)
- deleted 7y ago[deleted]
- catalogia 7y agoWith uBlock Origin/uMatrix, it's possible to block all Facebook domains on every site except on facebook.com itself. With DNS-based blocking that sort of nuance isn't possible; it's an all-or-nothing approach.
- tonymet 7y agosee pihole
- matthewaveryusa 7y agoTo elaborate a bit more, pihole is essentially this (dnsmasq + banlist), but with a pretty UI and admin page. Running your own DNS server is something more people should do and it took me all of 20 minutes to set it up on my docker homeserver with no prior knowledge of DNS except for 'it's the thing that translates domains to ips' and 'it's the thing on port 53'
- tomc1985 7y agoTomato firmware has something like this as well ... dnsmasq + blocklists
- pmoriarty 7y agoI've been using privoxy forever, along with 255.255.255.255 entries in /etc/hosts for domains I want to block. Not sure what using dnsmasq would buy me over this setup.
- deleted 7y ago[deleted]
- sneak 7y agoWorks on all devices, including mobile phones and tablets.
- 9dl 7y ago* Connected to wifi with installed dnsmasq * * If device do not use public (like 1.1.1.1) or custom DNS
- rndomsrmn 7y agoYou can also redirect those public dns servers on you router to your local Dnsmasq server with iptables.
- 9dl 7y agoNope You should not Or you completely compromise DNS chain and as result you can not trust results of dns resolve
- sliken 7y agoCould you explain? I don't use dnsmasq, but I do use unbound. I do block outgoing port 53 (UDP and TCP) and force the use of my unbound server. Quite a few apps and devices ignore the DNS recommendations provided by radvd (for ipv6) and dhcp (for IPv4). That way I can block youtube, instagram, netflix, imgur, reddit, and similar services that my kids are addicted to if they are avoiding homework and the like. How exactly does that "compromise DNS chain"? Unbound is DNSSEC aware, and talks to the same root servers that the ISP, google, opendns, or similar services would talk to. Sadly DoH will make this much more difficult.
- mirimir 7y agoIf tunneled DNS becomes prevalent, these hostname/domain approaches won't work. So it'll come down to blocking at IP level. And that will likely be harder.
- zamadatix 7y agoThat doesn't really have anything to do with the tunneling of DNS. Authentication + ignoring the local resolver do.
- Spivak 7y agoI mean it’s not really the fact that it’s hard coded. On my network I redirect all DNS traffic to my local resolver. Doesn’t matter if an app tries to hit 8.8.8.8 or whatever. The bit that will prevent me from pulling this trick in the future is the fact that it’s encrypted.
- zamadatix 7y agoI meant hardcoded authenticated DNS i.e. something you can't just blind redirect or configure the destination of. Reworded to say hardcoded while ignoring the local resolver for clarity. Encryption is technically the hard wall of "technically infeasible" but I say authentication because at that point you start getting massive delays in things being operationally feasible since you're waiting for things to give up on resolving rather than signaling it's unresolvable/a bogus location.
- mirimir 7y agoI meant stuff like DNS over HTTPS (DoH). If you trust whatever app is doing DoH, that's fine. But if you don't, it's nontrivial to even know what resolver it's using. Let alone forcing it to use a resolver you want. Edit: So that's tunneled DNS. You could also call it encrypted DNS, I suppose. But then, you could say something similar about VPNs, instead of calling them tunnels. Hard-coded authenticated DNS would be hard too, but it's at least possible that you could see what resolver it's using.
- vinni2 7y agoWhat’s the difference to pihole?
- _virtu 7y agoThis is actually half the reason that I use pi hole.
- pfundstein 7y ago"what's the difference" is half the reason you use Pihole? I think you meant to reply to OP.
- rndomsrmn 7y agoPihole does not make use of dnsmasq's build in option to block entire domains (address=/ads.com/::). This list is also optimized because hostnames that match a domain filter are not included, reducing the size a lot.
- sneak 7y agoYou’re better off using a DoH client like unbound and pointing it at a nextdns.io upstream. dnsmasq simply isn’t very good.
- 9dl 7y agoWhy dnsmasq? Why not unbound/bind/etc?
- arminiusreturns 7y agoEach has a use case. dnsmasq has an easier barrier to entry, so I have seen people use it during prototyping before implimenting unbound/powerdns/bind etc, but often those can be much more complicated setups. Most edge routers provided by ISP's are running dnsmasq on the underside.
- 9dl 7y ago>an easier barrier to entry I'd say opposite It had less examples and docs compare to unbound. At least that was my reason to setup unbound 2 years ago >Most edge routers provided by ISP's are running dnsmasq on the underside. True and sad
- ikeboy 7y agoThe problem with things like this is it's hard to disable on a case-by-case basis. I enabled something similar in a VPN and found that certain redirecting tracking links from emails were blocked. Ok great, they don't know that I clicked on the link, but also I don't know what the link led to, since it was blocked, and it was something I actually wanted to go to.
- unicornporn 7y agoWhich is why uBlock and/or uMatrix is the more usable option.
- pfundstein 7y agoDesktop and Android users can do this, but iPhone users are still pretty much limited to DNS-based blockers.
- fosefx 7y agoI mean, they can install Firefox. (With uBlock)
- maxmouchet 7y agoFirefox on iOS doesn't supports (Firefox) extensions. However Safari does supports content blockers (such as 1Blocker).
- rchaud 7y agoIt is for this reason that I still cannot use an iPhone as my main device. In spite of the many advantages of iOS devices (camera quality, resale value), it is still primarily a mobile browsing device for me. So the fact that I can't replicate my desktop browsing setup on it, extensions and all, means that I'll be sticking w/ Android and hopefully move towards a Google Play Services-free implementation.
- 7y ago
- 3xblah 7y agoGeneral policies * Should not break useful websites or apps * Blocks tracking servers * Blocks advertising servers * Blocks analytics servers * Blocks fake websites * Blocks malware servers * Blocks webminers A. "useful websites or apps" B. "tracking servers" "advertising servers" "analytics servers" "fake websites" "malware servers" "webminers" If B is larger than A, then a whitelist for A is easier to maintain than a blocklist for B. Following this logic is not for everybody, much depends on the user's particular web/app usage, but it has worked for me. It forces an otherwise naive user like me to get to know the "useful websites" and "apps" better, e.g., to be aware of the domains and any third party resources they are using. Some are much more dynamic than others. Thus, some may require constant attention where others may only require an upfront, one-time sunk cost of my time. Whereas reading through continually updated "blocklists", lists of servers that purportedly have nothing to offer me, is not something I want to be forced to spend time doing. How can we know that the people making the blocklists are not in collusion with the people behind the servers listed in B. At some point, we will be forced to look at what is listed in the blocklists. I would rather spend that time on a personalised whitelist.
- koolba 7y agoBuilding a personal whitelist is almost a right of passage. One personal annoyance is sites that use things like CloudFront and regularly change the host without assigning a vanity CNAME so you cannot simply whitelist *.cdn.example.com.
- zzo38computer 7y agoStill, the stuff listed B is not generally a problem with applications other than the web browser. If I use email, NNTP, curl, ifMUD, etc, then it isn't going to access servers that I do not specify with each request. Such software is simpler than the web browser; the web browser is a mess.
- 3xblah 7y ago"... the web browser is a mess." s/web/graphical &/
- pabs3 7y agoAt this point I wonder if a whitelist approach might be better for accessing the web. Does anyone know of any solutions for that?
- tsukurimashou 7y agosee top comment
- scoutt 7y ago> DNS over HTTPS will prevent clients in your network from using the default local DNS services. Relevant: Windows will improve user privacy with DNS over HTTPS https://news.ycombinator.com/item?id=21562295 https://news.ycombinator.com/item?id=21562295
- rndomsrmn 7y agoMozilla added a feature to allow users to disable DOH network wide (also supported by the notracking list). Info from notracking: https://github.com/notracking/hosts-blocklists#dns-over-https-doh https://github.com/notracking/hosts-blocklists#dns-over-http... Info from Mozilla: https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https https://support.mozilla.org/en-US/kb/configuring-networks-di... Not sure if Microsoft will do something similar? Else there is still the option to set up your own (local) DOH server and let your router route all DOH traffic to your local DOH instance.
- scoutt 7y agoAFAIK, being HTTP, you won't be able to differentiate and/or route it. And it can be done outside the control of the OS or browser (with js embedded in a page, application, etc.) so even if you configure your browser/system, it still will pass through filters unless whole domains are filtered? Since pihole and dnsmasq are already requiring disabling DoH, I see DoH as the dead of these kinds of adblock systems.
- rndomsrmn 7y agoYou will know on forehand what the fixed DOH servers will be, how else would you be able to locate them? If for example they will use the 1.1.1.1 DOH instance, you can simply redirect all localnet 1.1.1.1 (80/53) traffic to your own local (DOH)DNS(masq). Besides that there must be a fallback option for network admins, since using dns filtering and localnet dns is very common in enterprise. Firefox implemented a canary domain, specifically designed for this purpose, see: https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli...