12 ms·
Pi-hole is great, but it cannot block all kinds of ads since it relies on DNS redirection. YouTube ads are notorious for this, for example
by Crestwave 5y ago
Pi-hole is great, but it cannot block all kinds of ads since it relies on DNS redirection. YouTube ads are notorious for this, for example
- ignoramous 5y agoI don't think uBlock Origin can block YouTube ads either?
- GekkePrutser 5y agoYeah and its functionality is also being eroded by apps using things like DoH. I use both but I don't think the network level blocking will work forever.
- josephcsible 5y agoPlease don't use DoH as an evil advertising bogeyman. It's a huge win in the fight against censorship and surveillance, and everything that it lets advertisers do can be equally done by hardcoding an IP address in the app instead.
- topranks 5y agoDoH itself is fine. But to win against “surveillance” you need to make a smart, conscious decision about who you want to give your browsing history to. For me, I’d rather my ISP sees my DNS, than all that data is sent to some American mega-corp keen to hoover up every last datapoint about me they can. My ISP can for the most part look at HTTPS SNI field and see all the domains I access anyway. So switching to say, Google DoH, only means that now Google have that list as well as my ISP.
- josephcsible 5y ago> some American mega-corp keen to hoover up every last datapoint about me they can That's a really good description of both Comcast and Verizon. Not so much of Cloudflare though - they seem to actually care about people's privacy. > My ISP can for the most part look at HTTPS SNI field and see all the domains I access anyway. So switching to say, Google DoH, only means that now Google have that list as well as my ISP. Isn't this just an argument to hurry up and get eSNI/ECH rolled out everywhere?
- topranks 5y agoAbsolutely reason to promote ECH. Sure Cloudflare are better than those other big US ISPs. But for those of us in the EU, where such practices are illegal, we may want to think twice about giving our data to Cloudflare (who are subject to requests from US govt for instance.)
- josephcsible 5y agoEven in the EU, couldn't there still be a privacy benefit? Set aside for a minute what's legal and illegal, and just consider what entities are capable and incapable of. By using a DoH provider (that sees what domains your client IP is looking up) other than your ISP (that knows that your client IP goes with your real-life identity), there's now no single entity capable of associating your real-life identity with which domains you've looked up.
- GekkePrutser 5y agoWell, it does break pihole. And I already use trusted DNS providers (over TLS) so it's not really an issue. My provider can't see my DNS lookups. Also, in the EU providers are not allowed to use deep packet inspeciton so they only know your queries if you use their own DNS. Hardcoding an IP is really difficult to do for adtech providers for 2 reasons: 1) They usually subcontract to cloud providers that don't guarantee IPs 2) It breaks SNI (Server Name Indication), also heavily used on cloud services There's better ways to do secure DNS than DoH, like DoT (DNS over TLS) I like secure DNS but I still want my own server to be the middleman. With DoH this isn't easily possible, especially on mobile due to the root CA issue. DoH is normally implemented using a major player like CloudFlare. Sure, they promise not to look at it. But the phrase "Don't be evil" still is pretty fresh in my mind. But anyway, it's a moot point. Even if we could block DoH somehow (we can't due to certificate pinning and Android no longer allowing to add a global root CA since Android 7), app providers could just implement their own lookup system or something. Whether we like DoH or not it's here to stay.
- josephcsible 5y ago> Well, it does break pihole. Sure, but that's only because your computer can't distinguish your Pi-hole blocking DNS to block ads from an evil ISP blocking DNS to censor you. And if your device supports DoH, can't you just point it to one of the many publicly-available DoH servers, or set up a DoH server on your Pi-hole and then point at that? > It breaks SNI (Server Name Indication), also heavily used on cloud services They can just hardcode the IP in the hosts file, not in the client program. Then SNI will still work normally. > There's better ways to do secure DNS than DoH, like DoT (DNS over TLS) Then the people who want to do censorship and surveillance will all just block port 853. It's a feature that DoH is hard to distinguish from other HTTPS traffic. > I like secure DNS but I still want my own server to be the middleman. With DoH this isn't easily possible, especially on mobile due to the root CA issue. Can't you set up your own DoH server with its own domain name, get a Let's Encrypt certificate for it, then point your mobile device at that? > DoH is normally implemented using a major player like CloudFlare. Sure, they promise not to look at it. But the phrase "Don't be evil" still is pretty fresh in my mind. Isn't the alternative that your ISP is definitely looking at it?
- beertoagunfight 5y agoWhat's DoH?
- hkt 5y agoDNS over HTTPS. It is a new(ish) way to do lookups that deals with the insecurity of most DNS setups (where packets are often neither signed nor encrypted) by hitting a resolver over https. Often the application will hard code the resolvers it intends on using, which leads people to believe it is adtech as it allows apps to bypass blocking by PiHole and the like. It, like most tech, can be used or abused.
- topranks 5y agoI think that’s the fundamental change it brings. Once the system, or network admin would set the DNS servers up and everything on the system would use those. There is no reason why that paradigm couldn’t continue and move to DoH. The other change is that applications are now bypassing the system-configured DNS and sending requests (and thus data about what you are looking at,) where the application wants. The “centralisation” issue also comes into this. But again, the change from a system-level to per-app setting could happen with regular old plaintext DNS. DoH is part of the discussion in both cases, which clouds the debate.