11 ms·
Maza – Like Pi-hole but local and using your operating system
- vezycash 7y agoI've been using adguard's dns to block ads on my phone* because pi-hole isn't an option for me at the moment. Also set it on a colleague's phone and he's thanked me severally for it. * (dns.adguard.com private DNS in network settings on android pie)
- politelemon 7y agoSimilar to that I've been using NextDNS - in addition to the adblock you also get custom whitelist/blacklist, analytics... and also supports DNS-over-TLS (works well with Android's Private DNS feature) and DNS-over-Https See: https://nextdns.io/ https://nextdns.io/
- k__ 7y agoWhat can the analytics tell me?
- hnarn 7y agoI've been using nextdns and I like it: for one thing, it can tell you the amount of blocked DNS queries, but it's also very helpful for troubleshooting since you can see the log of what was blocked, when, and why (which blocklist). You can then completely disable the blocklist, or whitelist specific entries if you prefer. It's a level of customization that I don't believe other DNS adblockers provide since many of them are designed to "just work".
- okneil 7y agoI wish iOS also supported private DNS natively. Seems like it would be right up Apple's street.
- tuananh 7y agowhat is private DNS?
- vezycash 7y agoMy explanation was wrong... Google support page explation for private DNS doesn't explain anything. Just recommends leaving it on.
- jeroenhd 7y agoIt's more than that, private DNS is not just a different DNS server, it's a DNS over TLS (DoT) server. This means encrypting the lookups to prevent the ISP from tracking the host names you visit. Many DNS servers don't support DoT and some support DoH (DNS over HTTPS) instead.
- tuananh 7y ago> Private DNS allows you to set the DNS server the phone should use instead of your ISP's. iOS does support that.
- clairity 7y agothey recommend leaving it on because then all your dns queries go to google and no one else by default--their "private dns" defaults to the very unprivate google dns servers.
- k__ 7y agoI think it's DNS with in-flight encryption.
- tuananh 7y agooh, like dns over tls ?
- solarkraft 7y agoyes.
- hpliferaft 7y agoI was a happy Adguard user for several years but found that some ads have come through lately. I did some research and switched to Blokada, which works well--sometimes too well; I have to temporarily deactivate it to use certain apps when I'm not on WiFi.
- 1_player 7y agoGreat work! One suggestion: please make blocklists configurable.
- tanrax 7y agoIt is not difficult, I take note to implement it.
- IngvarLynn 7y agoThat was my thought exactly when I decided to upgrade the very much analogous script https://raw.githubusercontent.com/notracking/hosts-blocklists-scripts/master/notracking_update https://raw.githubusercontent.com/notracking/hosts-blocklist... . The end result sort of works, but I deeply regret not using sane language for the task. Result: https://gist.github.com/ingvar-lynn/f0b84d5f750bd2e555d3f1ded6ef159e https://gist.github.com/ingvar-lynn/f0b84d5f750bd2e555d3f1de...
- stfwn 7y agoFwiw, you can run Pi-hole locally just fine. But using the hosts file like Maza does may be a little bit faster than running a DNS-server.
- fuzzy2 7y agoOn Windows, a large hosts file may lead to noticeably slower name resolution performance. Maybe it's less of a problem on Linux/macOS...?
- vezycash 7y agoIt did happen to me. I used StevenBlack's Unified hosts + fakenews + gambling + porn + social It's over 1.4mb. And after any edit to the host file, it'd take minutes before I could browse. (Hard drive) When I switched to SSD, the delay dropped to less than a minute. For domains I already visited, cached, there were no perceptible resolution delays.
- jeroenhd 7y agoI learned this the hard a few years back. The lookup performance was good enough, but every time I woke the computer up from sleep or rebooted it, it would spend ten minutes maxing out one or two cores trying to process a hosts file blocking all known malware/spyware/adware domains. This took me ages to find the cause of, I had to use a lot of highly-escalated debuggers and such to figure out what the "system" process was trying to do that was costing so much time. Once I cleared out the hosts file, the problem was resolved.
- t0astbread 7y agoI'm on Linux and I have had a large hosts-based block list for a few months now and I haven't noticed any slowdowns so far.
- driverdan 7y agoI have a large hosts file on my Mac with Steven Black's blocklists. It takes a few seconds to load in vim but doesn't seem to cause any problems with lookups.
- tuananh 7y agothe one reason i use pihole is to block ads network-wide. this kinda defeats that purpose.
- nxpnsv 7y agoyes, but you have pihole for that... this is if you don't need or want to issue a network wide block
- tuananh 7y agoi couldn't think of an use case for this? can you explain what would you use this for? if you already have pihole?
- bauerd 7y agoWhen you don't control DHCP (or the network as a whole)
- Eikon 7y agoYou don’t have to control DHCP in order to use Pihole. Supplying custom nameservers at the os-level works too, as it should be.
- nxpnsv 7y agoThe use case is when you don't have a pihole. If you already run pihole I agree, this is not a useful addon. But what if you're at school or work with just with your laptop. Is it possible one might want run Maza instead pihole locally? I think possibly yes.
- Normal_gaussian 7y agoFor use on a laptop that you take into other networks (coffee shops, friends houses, work / client businesses). For use on a desktop in a network you do not control (e.g. many devs have complete local control over their own machine)
- xtf 7y agoNetwork Wide > Pi-hole Browser > Ublock Local System > hosts-file Android (root) > Adaway (does hosts-file)
- hnarn 7y agoI've been using https://nextdns.io/ https://nextdns.io/ for a while and I really like it. You can do DNS over HTTPS through Firefox (sadly not on an OS level in Windows for example, but that's fine -- I'm sure OS level support works better on Linux), and it supports a lot of user-level customization. You can add and remove entire blocklists, you can black/white-list specific domains, see logs of your blocks, some analytics, create your own redirects etc. and it doesn't cost you a thing. The main website does a pretty good job of explaining the selling points. You can use it as-is but if you want user-specific configuration you'll get a custom URL that looks something like "https://dns.nextdns.io/c8g88a" https://dns.nextdns.io/c8g88a", and whatever comes in that way will use your settings and will be logged as per your configuration (of course, you can disable logging).
- darkteflon 7y agoI’ve just looked into this - it looks excellent. Can I ask: is this an all-round superior solution to running your own pi-hole? I set up dual redundant pi-holes on raspberry pi 4s on my home network but switching all devices to NextDNS would give me access to filtered DNS even when away from home, plus save me the trouble of running two raspis (including two Ubuntu instances) just for that purpose. Could anyone knowledgeable in such things suggest any downsides to a wholesale switch?
- weego 7y agoI've been a user since it was first mentioned on HN and the major issue at the moment is the performance. I often have to turn it off to get sites to resolve at all, otherwise chrome hangs indefinitely. Having said that it's free (beta) right now so that's a statement of fact and by no means a complaint
- robertcope 7y agoYou're saying you have this issue with NextDNS? I've been using it since it was mentioned here, as well, and have had zero issues that were not self-created. FWIW.
- swinglock 7y agoWho is this for, what's the point? If you're using a computer on which installing this software is an alternative, you can install a web browser with an ad blocker, which performs much better than DNS based filters. If you're not using such a computer, Pi-Hole proves DNS filtering and this software doesn't. What's the use-case between these two that isn't already covered?
- imglorp 7y agoChrome, for example, has banned some adblockers. Makes sense to me.
- martimarkov 7y agoOut of curiosity which ones and is there a common pattern in their blockage philosophy?
- imglorp 7y agohttps://www.zdnet.com/article/opera-brave-vivaldi-to-ignore-chromes-anti-ad-blocker-changes-despite-shared-codebase/ https://www.zdnet.com/article/opera-brave-vivaldi-to-ignore-...
- Larrikin 7y agoThey banned the best one in my opinion https://adnauseam.io/ https://adnauseam.io/ Blocks ads and helps poison the data they have collected on you
- t0astbread 7y agoSoftware that's not running in a web browser but on a machine where you can install a local DNS proxy. It's not a broad use case but it's also really cheap to do and doesn't have a lot of maintenance cost.
- littleweep 7y agoA lot of websites (news sites especially) detect in-browser ad blockers and urge users to whitelist the site before continuing to read the article. This is a good workaround for that use case.
- StreamBright 7y agoI just started to write this in Rust a few months back. Thanks for this project it is fixing most of my problems with Pi-hole.
- amelius 7y agoThe point of Pi-Hole is that you can't hack it that easily compared to software installed on your local computer.
- alpaca128 7y agoHow is it supposed to be harder to hack? I thought the main point is to have the blocking enabled in the whole network, including devices like smartphones.
- amelius 7y agoBecause the Pi-Hole doesn't run untrusted code, like a personal computer does (e.g. Javascript, installed applications, etc.). Same holds for smartphones.
- rovr138 7y agoLots of people run other stuff on the devices they run Pi-Hole on.
- jlgaddis 7y agoI'd consider the web-based administration interface to be "untrusted code" -- and there just a remote code execution vulnerability (due to very insufficient input validation of MAC addresses) discussed here yesterday [0] . [0]: https://news.ycombinator.com/item?id=22714661 https://news.ycombinator.com/item?id=22714661
- wp381640 7y agoI have a docker-compose.yml locally with: dnsmasq -> pihole -> stubby The first dnsmasq is for local .test domains for dev. Works well for when i'm not on one of my networks.
- XelNika 7y agoWhy not configure your local .test domains in your Pi-hole? That's also dnsmasq, you can use the same configuration options.
- steveharman 7y agoI wonder why the pi-hole tram doesn't also offer a paid tier (that they host), to help those who can't or don't want to roll their own? It could help fund future development and maintrnance costs.
- lonelappde 7y agoMaybe they already have a full-time job? Anyway, it's free software. Anyone in the world can do that if they want. You can do that. Also, it's poorly scoped. Pihole is just an app. Any ownclowd provider can more efficiently host it along with a bundle of every other app people want to "own" but not run locally.
- GordonS 7y agoWhile this is true, I'd put much more trust in the PiHole team than I would some random corp - by the very nature of what they've built, and how they licensed it, I'd expect them to be privacy centric. By paying for such a service, I'd also feel like I was contributing to the ongoing maintenance of PiHole by the core team. I think the GP's suggestion is a fantastic one!
- lonelappde 7y agoOh, this is a wrapper for running dnsmasq. It's lighter weight than pihole but less user firendly. Not sure why the readme tries to obscure that. https://github.com/tanrax/maza-ad-blocking/blob/master/maza https://github.com/tanrax/maza-ad-blocking/blob/master/maza
- XelNika 7y ago> Not sure why the readme tries to obscure that. I don't think it does, dnsmasq is optional. It does configure dnsmasq regardless, but that configuration only applies if you install and enable dnsmasq. As far as I can see, the script does none of that nor does it change /etc/resolv.conf. The readme is very clear about needing dnsmasq for wildcard blocking. The script also modifies the host file which will apply regardless.
- dmclamb 7y agoI use pihole for my entire home network as primary DNS and opendns for secondary (long time user of opendns, since before Cisco bought it). I also have VPN setup for remote access (esp. for mobile). I use ublock origin at the browser level. These are layers of protection from undesired content (ads, malware, porn, etc.). If one fails, hopefully the next layer will provide desired protection. I have kids approaching teen years. There is no magic bullet, and we still monitor and limit their screen time. How would you improve this setup? Just curious.
- justanotherhn 7y agoAre you trying to shield your teenage kids from seeing porn by accident or actively seeking it out? If it's the later you've already lost - presumably they have 4G.
- deleted 7y ago[deleted]
- Tempest1981 7y agoOr at least one friend whose parents aren't tech savvy, and aren't home.
- throwaway4787 7y agoCan someone explain how the use case differs from simply using a well-curated hosts file? (like Steven Black's)
- rovr138 7y agoThere’s some issues with them being too big and using a lot of resources. You can even find comments about it on this thread
- bestouff 7y agoOr if you already run dsnmasq you can: - uncomment this in your dnsmasq.conf: addn-hosts=/etc/banner_add_hosts - put this in a file in /etc/cron.daily: wget -O /etc/banner_add_hosts 'https://pgl.yoyo.org/adservers/serverlist.php?showintro=0&mimetype=plaintext'
- leeoniya 7y agoyep, i do this on my edge OPNSense appliance, except with https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts
- achairapart 7y agoI'm looking for a simple tool to setup and switch to DNS over HTTPS at the OS level (MacOS, in this case), with no success. With it, I would simply switch to one of the many pi-holed/filtered DOH services[0] out there, or even roll my own on a cheap VPS. On iOS there is DNSCloak which is excellent, Android 9+ has built-in support (Private DNS). [0]: like pi-dns.com or blahdns.com
- ddrt 7y agoOut of ignorance, how does DNS Cloak differ/compare to NextDNS?
- achairapart 7y agoNextDNS is a commercial solution, there will be more limits to the free plan when it will be out of beta. DNSCloak is just a tool that let you choose different DNS resolvers, even your very own.
- petre 7y agoI'm using this whenever I have a working server lying around. Unbound works great. https://github.com/gbxyz/unbound-block-hosts https://github.com/gbxyz/unbound-block-hosts
- p2t2p 7y agoI'm using simple https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts. Puts everything into hosts file.
- 4nof 7y agoI found there is a docker container of pihole which means it can run on anything including Windows! I tried it and it works in a docker container on windows just fine! pihole docker steps: (prereq: install docker https://www.docker.com/products/docker-desktop https://www.docker.com/products/docker-desktop) 1.setup your docker-compose.yml file with the one listed on pihole page https://hub.docker.com/r/pihole/pihole/ https://hub.docker.com/r/pihole/pihole/ (starts with version: '3'). 2. save and do "docker-compose up -d" 3. do "docker ps" and ensure your pihole is running. 4. Go to network settings and set your DNS to 127.0.0.1 and ::1 like this: https://mayakron.altervista.org/wikibase/show.php?id=AcrylicWindows10Configuration https://mayakron.altervista.org/wikibase/show.php?id=Acrylic... 5. if the docker container is ever stopped, you will need to reverse the setup step 4 to get back internet. Hope that helps all you windows users who want a DNS blocker pihole on your machines!
- jdc0589 7y agoI've been doing this for the past year or so. couldn't run pihole network wide because too many shady "deal /discount" sites my girlfriend uses kept breaking, so this was my alternative.
- mcovey 7y agoFor anyone running OpenWRT, you can install the adblock package to accomplish roughly the same thing as Pi-hole does. I don't believe it supports some advanced features like DoH/DoT or DNS resolution (e.g. a1b2c3.example.com -> ad-server-that-should-be-blocked.com), but it does the basics - custom host file sources, additional blacklist rules, whitelisting, and quick enable/disable for troubleshooting. It also has an option to force all DNS traffic (port 53, so again it won't catch DoH/DoT) to go through the router. Occasionally I forget I've done this and tried `dig foo.bar @1.1.1.1` and gotten confused until I remember that my router is forcing that DNS lookup to go through it first, and then through the router's configured DNS resolver.
- touristtam 7y agoYou can use dnsmasq on OpenWRT and other packages that void the need for an additional pi-hole.