21 ms·
AdGuard Home: Network-wide ad- and tracker-blocking DNS server
- zukzuk 3y agoI looked at Pi-hole recently but went with AdGuard Home. Nicer UI and nicer everything by all appearances. There's also a surprising amount of customization for something this slick, like being able to defer to my internal DNS for local private domain queries, etc. I'm not entirely sure why AdGuard is giving this away, and maybe I should look into that, but seemed like a relatively low-risk decision to go with this for now. And I can't say enough about how much more pleasant using things like the NYTimes app has been without the obnoxious ads.
- andix 3y agoYes, it’s really awesome. The split-dns feature has all the options you would imagine. I thought i would need a second dns server behind it, but i could add all the rules I need right into adguard home. It even supports DoT and DoH upstreams, which is still not a thing with many home routers. Edit: here are the docs: https://github.com/AdguardTeam/AdGuardHome/wiki/Configuration#upstreams https://github.com/AdguardTeam/AdGuardHome/wiki/Configuratio...
- madduci 3y agoThey can expand their user base and when they have acquired a certain amount of people, switch to a licensed model?
- andix 3y agoThe main repo is GPLv3: https://github.com/AdguardTeam/AdGuardHome https://github.com/AdguardTeam/AdGuardHome They already have many other commercials products and I guess also the default filter rules are very good because of their experience in the domain. But I think you can use it completely without the AdGuard servers and use other filter list sources.
- andix 3y agoAbout the give-away-for-free aspect I was also wondering. Do they maybe configure their dns servers as default upstream and hope many people keep the defaults? DNS is one of the best technologies to do data mining and sell the data. I guess it's also why all those easy to remember dns servers like 8.8.8.8 and 1.1.1.1 exist. Google and Cloudflare for sure don't do it just to be nice. Disclaimer: adguard claims not to sell any customer data.
- throwaway742 3y agoDoes AdGuard support regex matching?
- Brajeshwar 3y ago> I'm not entirely sure why AdGuard is giving this away Here is my reasoning. I can read up the documentation and set it up and get it working. I'm going to brag to my friends about how my home network has no pesky ads and stuff. They will ask me to “Set up for me, Set up for me.” I cannot help them maintain, even if I do set it up for them, so -- I'm going to say, “You know what, instead of that complexity, they have a simple app-based setup that just works for just $29 a year for your whole family.” See, I just got five of my friends to download and buy the service in that dinner party. I believe this is the same philosophy of todays' tech Startups -- have an Open Source Product but build a commercial business on top of that.
- zymhan 3y ago> like being able to defer to my internal DNS for local private domain queries, etc. PiHole supports Conditional forwarding
- JadoJodo 3y agoI ran a competing project[0] on my home network for a few years before I discovered NextDNS[1]. What I lost in performance (requests don't leave my house) I gained in portability: ALL my devices can take advantage – at home and away – and time-saved. PiHole works 90% of the time, but when it did stop working, I'd have to spend a bit of time fixing it. At $20/year, I simply couldn't compete with NextDNS. Note: This isn't a shill for NextDNS; I love these kinds of projects and think they absolutely should exist, but NextDNS just happens to be one of those dead-simple SaaS tools that is an insanely good value. 0 - https://pi-hole.net/ https://pi-hole.net/ 1 - https://nextdns.io https://nextdns.io
- drewg123 3y agoI love NextDNS. The one (fairly huge) issue that I have is that it cannot handle captive portals when its enabled on my iPhone. So if I'm joining the wifi on a plane, etc, I need to remember to turn it off. This means that I cannot recommend it to my non-technical friends.
- maronato 3y agoI’ve been using NextDNS for a little while and don’t remember having issues with captive portals on my iPhone. Maybe something changed?
- hipsterstal1n 3y agoMost likely it's due to the different lists you can add or use on NextDNS. I also have issues with captive portals (I run a number of lists on NextDNS) and I just flip it off and on when I need to.
- s0ss 3y agoNeat! Similar: If you happen to run pfsense on your network, check out pfblockerng, I really like it!: https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html https://docs.netgate.com/pfsense/en/latest/packages/pfblocke...
- politelemon 3y ago> Runs on your OpenWrt box Where are you seeing that? The only reference to OpenWRT I see is in the "Projects that use AdGuard Home" section which links to a different project. Otherwise that's a misleading title - this is a PiHole alternative.
- cricalix 3y agoIt absolutely runs on OpenWrt - simple as opkg install, then setting it up and sorting DNS redirection as needed.
- masfuerte 3y agoYes, but the title suggests that OpenWrt is the only place it runs. Which is misleading.
- dsissitka 3y agohttps://openwrt.org/docs/guide-user/services/dns/adguard-home https://openwrt.org/docs/guide-user/services/dns/adguard-hom...
- rekabis 3y agoWhat’s the difference between this and just using their DNS addresses with the force redirect option enabled?
- skottenborg 3y agoThe internal DNS records are very handy if you host local services.
- Naac 3y agoAnyone know of an Adguard home or pihole equivalent service I can run as part of OPNSense? I currently have a different machine dedicated to pihole, but it would be intriguing to have something built in. I would imagine split DNS and firewall rules would be simpler this way.
- _micheee 3y agoThe built-in unbound dns server has support for blocklists, maybe you want to give it a try: https://docs.opnsense.org/manual/unbound.html https://docs.opnsense.org/manual/unbound.html
- moviuro 3y agoUnbound with tags? * https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering/tags-views.html https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering... * https://try.popho.be/securing-home3.html https://try.popho.be/securing-home3.html * https://git.sr.ht/~moviuro/moviuro.bin/tree/master/item/lie-to-us https://git.sr.ht/~moviuro/moviuro.bin/tree/master/item/lie-...
- bityard 3y agoI'm in the process of migrating my OPNSense to a virtual machine so that I can run whatever network-related services I want right along side it in a container or VM. I used to scoff at those enterprising homelabbers who apparently stuck their firewall in a VM just because they could but I get it now. It's super nice to be able to just snapshot and back up the whole VM, and run whatever you want alongside it. (Although I will limit the box to specific network management things like AdGuard Home.)
- vin047 3y agoDitto, just recently set mine up this way. Will never go back to ISP or proprietary routers.
- cycomanic 3y agoAdguard runs directly on opnsense. https://0x2142.com/how-to-set-up-adguard-on-opnsense/ https://0x2142.com/how-to-set-up-adguard-on-opnsense/
- winstonprivacy 3y agoSadly for the AdGuard team, there isn't much of an audience for this. It's one of those things everyone says they want but few people will actually install one, much less maintain one over time. Add to that the wife-forced uninstalls and the total long-term audience for this is (no kidding) in the thousands.
- breckenedge 3y agoMy spouse’s device is on a pihole exclusion list. Can you not do this with AdGuard?
- zukzuk 3y agoYes, you can definitely use it selectively.
- jraph 3y agoWhat is the reason for someone in the network to not want the filtering? Does this break some websites? My own devices are covered, I definitely want full filtering even when not at home and my devices are completely hackable, but I'm wondering if such a tool would be a convenience for other people using the network in particular with less hackable devices, and people likely to use my network are likely totally uninterested in ads, but I don't want this to be a pain.
- breckenedge 3y agoYes, it breaks some websites and apps that they use for work. My pihole also only runs on my “private” network, the “guest” network is not filtered. Apple’s Private Relay also does not work behind a pihole.
- grebly 3y agoHow does it compare to pfblockerng on pfsense?
- deleted 3y ago[deleted]
- rpnx 3y agoDon't do this. Network firewalls are harmful. Let people configure their own firewalls on device. Having to VPN around network blocks is annoying to say the least. Network firewalls are harmful and just a lazy excuse for bad client security.
- drcongo 3y agoI run AdGuard Home on a Pi and it's fantastic. I was running PiHole previously and found it endlessly problematic, I rarely have to even think about AdGuard Home.
- triyambakam 3y agoCoincidentally I just set up OpenWRT [1] on a NanoPi from FriendlyElectric. How would this fit into using Wireguard? Or, how would I go about that? It seems like there might be something conflicting about running both, but I am very new to it all. [1] It is actually running their FriendyWRT variation which came with the precompiled drivers for getting a Realtek USB wifi adapter to work, otherwise stock OpenWRT would work as well
- vosper 3y agoWhat does this break, if anything? Anyone run into sites or apps where Adguard Home needed to be disabled? How easy was that?
- fursund 3y agoPerhaps obvious, but if you’re using mixpanel or posthog for analytics on anything you build, you’ll have to put them on exclusion lists, in order to be able to use their analytics platform.
- mnt3 3y agoDepends on the blocklists you're using. I broke Google search sponsored links, some Slickdeals links, and the meta quest app store. You have the ability to whitelist as well if you want to unblock some things. I'm running it in a docker container and then pointing my router at it.
- pandemic_region 3y agoHappy AdGuard user here. It's running directly on my EdgerouterX so no need for an extra device to maintain. I really love the high level service blocking as well, blocking the whole of Facebook is just ticking a checkbox!
- ittan 3y agoUnsure if anyone here uses Technitium DNS(Opensource and free). It works on minimal hardware. I am running it on an Orange Pi 3 LTS. https://technitium.com/dns/ https://technitium.com/dns/
- mianos 3y agoAnd you can load the ad blocking lists into anyway so you get solid DNS, ad blocking and none of those random youtube spinners from rando dns issues. For nothing but a little configuration.
- az09mugen 3y agoYup, running it on a pi 4. Simple to set up and use, happy with it. I didn't know about Adguard but I don't want to try it even if it seems good.
- FuriouslyAdrift 3y agoI've been using it for years and love it. .Net based, so it is cross platform, too! There's a docker image if you want to go that route.
- yumraj 3y agoThis looks great. Qs: this says “ Technitium DNS Server is an open source authoritative as well as recursive DNS server” Are pi-hole/Adgyard also recursive DNS server or just a blockers? Edit: I’ve been using pi-hole for ages, trying to figure out if this has any advantage.
- roach360 3y agoCan't speak to Adguard: PiHole isn't natively recursive, but you can easily set up a service alongside pihole on the pi (or in another docker, if your pihole is a container) called Unbound which provides recursive DNS.
- yumraj 3y agoThanks, I’ll take a look at Unbound. I have it running on a Pi. I had a pfsense, which died a few days ago while upgrading from 2.6 to 2.7. I believe it was running Unbound.
- justaman 3y agoWill this work against ads on major streaming apps like prime, hulu, and netflix?
- Ninn 3y agoNo
- karolist 3y agoWorks fine, beautiful and simple UI, I have it on my Dell R230 homelab server, running inside a container under Proxmox VM
- int_19h 3y agoOne other neat thing about AdGuard is that it is available as a Home Assistant addin - and it does integrate with the rest of HA, so you can e.g. have a switch to enable/disable blocking as part of your dashboard.
- fignews 3y agoNextDNS also, just set it up :)
- dsheets 3y agoI contributed improved ipset support to this project. As far as I know, it’s one of the few off-the-shelf DNS servers that can insert result records into Linux ipsets to enable domain-based firewall policy. I run it on OpenWRT and use the ipset support to open the default drop firewall from my “smart” projector on my IoT subnet to NetFlix and YouTube. It sets the ipset entry expiry to the DNS TTL. Now, the only way for the machine to connect to the internet is to resolve a whitelisted domain and it can only access while the record is fresh. I haven’t encountered any issues so far. I take it that some Chinese users use this same functionality to selectively VPN domains to evade GFW.
- steeve 3y agoCurrently running this as a Home Assistant addon is
- steviedotboston 3y agocan this be used in conjunction with tailscale?
- dsheets 3y agoI use it with WireGuard.
- aantix 3y agoIs there something similar, say a proxy, that rewrites the responses to exclude certain ad patterns?
- miah_ 3y agoYes, Privoxy http://www.privoxy.org/ http://www.privoxy.org/ It comes with all the limitations of using a HTTP Proxy in today's world where SSL is everywhere.
- 2OEH8eoCRo0 3y agoI love AdGuard Home, been using it for years now after PiHole gave me issues.
- Crosseye_Jack 3y agoAlso runs on home assistant. The only thing to remember is when your updating HA (or you forget that your HA pi is not on the UPS, and you trip your GFI when doing home maintenance on your ring main) that your DNS also goes down. Side note: it’s always DNS…
- Dries007 3y agoExactly why I run my DNS on an old pi just for that and some minor watchdog stuff.
- raajg 3y agoBeen 4 months and I'm pretty happy with the following setup: PiHole + RaspberryPi + Tailscale With Pihole running on a tailnet all my devices use it by default as long as they're on the same tailnet. That way I have seamless ad-blocking even when I'm on cellular data or my friends' wifi networks.
- smarterhome 3y agoAdGuard Home is amazing! I used PiHole for a time but did run into small issues quite at lot. Mind you nothing serious but things like these are only really useful if they just work. Adguard Home works without any issues on my Pi setup via docker-compose [1] and it even runs on a second Pi as backup using a cool container called adguardhome-sync [2] to keep their configurations in sync. I am not seeing any ads in my network anymore and it is quite interesting to see how many tracking/ad requests are sent by some devices... 1 - https://thesmarthomejourney.com/2021/05/24/adguard-pihole-dns-ad-blocker/ https://thesmarthomejourney.com/2021/05/24/adguard-pihole-dn... 2 - https://thesmarthomejourney.com/2023/02/12/adguardhome-sync-instances/ https://thesmarthomejourney.com/2023/02/12/adguardhome-sync-...
- vin047 3y agoThe real eye-opener is when you start redirecting DNS 53 requests to your own DNS server and block DoT/DoQ/DoH – so many devices/apps just trying to reach out to their hardcoded DNS servers for tracking/ad targeting.
- briHass 3y agoUnsurprisingly, Google and Facebook IoT junk is the worst. They both hardcode their own DNS, and I've caught Google devices ignoring the DNS IP from DHCP (not the gateway) and attempting to resolve from the gateway (with external blocked)
- amelius 3y agoHow can this possibly work? I don't know much about how adtech works, but if I were Google I'd provide ad blocking detection to all of my clients. And it should be pretty simple to detect if parts of the network that are essential to my ads are being blocked.
- cyberax 3y agoI really hate that all these services break DNSSEC. I guess it can't be helped.
- stzsch 3y agoI got my glinet gl-axt1800 mainly for the adguard support out of the box, as a way to keep my smart tv experience sane. Works pretty well.
- teruakohatu 3y agoAre there allow lists for services such as Apple TV. Do smart tvs not fall back to hardcoded ipv4 addresses?
- stzsch 3y agoThere might be allow lists, but I fine tuned the domains manually when setting up the TV, as they may vary by region. My LG A1 does not hardcode addresses. I also rooted it to prevent updates from doing so in the future.
- teruakohatu 3y agoThanks for the info
- JoshTriplett 3y agoStanding reminder that any device smart enough to run a real web browser shouldn't use one of these and doesn't need one. uBlock Origin works much better for any device capable of running it, both in terms of user experience (the browser understands a block rather than a mysteriously failing request) and because it can block first party ads and clean up page layout. The primary use case for these is for blocking ads on devices that don't allow running a real browser and yet still shows ads, such as "smart home" devices, TVs, etc.
- johntash 3y ago> Standing reminder that any device smart enough to run a real web browser shouldn't use one of these and doesn't need one. Why not? Or why not use both? > The primary use case for these is for blocking ads on devices that don't allow running a real browser and yet still shows ads, such as "smart home" devices, TVs, etc. What about non-browser apps on mobile devices or even desktops? Lots of apps have invasive ads and are unlikely to offer an extension api to block them with.
- shiroiuma 3y ago>What about non-browser apps on mobile devices or even desktops? Lots of apps have invasive ads and are unlikely to offer an extension api to block them with. Simple answer: don't use those apps. Do you really need them?
- JoshTriplett 3y ago> Why not? Or why not use both? Because DNS-based blockers aren't visible to the browser, so they just look like HTTP errors or worse, and cause a variety of misbehavior. They're much more likely to produce errors that feel like the site just doesn't work. They can't distinguish between requests to different URLs on the same server, and many sites distribute both ads and content from the same servers. So they're always either going to miss ads or break sites, or both. Browser-based blockers can block some URLs while allowing others, in addition to many many other improvements like substituting no-op scripts for things the site expects to call (preventing sites from hanging because they're waiting on tracking, for instance). > What about non-browser apps on mobile devices or even desktops? Ignore "download our app!" prompts and stick with mobile websites wherever possible; Firefox Mobile has excellent adblocking via uBlock Origin. Look for ad-free alternative apps. If that isn't an option, purchase ad-free paid apps.
- gotschi_ 3y agoUnfortunately it is a 11mb install, which makes it quite unfitting for your usual openwrt device
- time4tea 3y agoYou might be interested in py-hole. It's just a python script and some dnsmasq configuration, it runs on openwrt, is free and close to zero cpu usage. https://github.com/time4tea-net/py-hole https://github.com/time4tea-net/py-hole
- vladgur 3y agoWith a self-hosted DNS internally, how do you handle fallback? For example if the box with Adguard Home or pihole crashes, can you configure your router or your devices in a way that would instead go to say cloudflare or google DNS?
- jerezzprime 3y agoI dealt with a less-than-ideally reliable pihole by configuring the pihole as the primary DNS, and an external DNS server as the secondary (most devices accept 2 or more IPs for DNS).
- 293984j29384 3y agoOn Windows that means your requests are queried against all DNS servers listed.
- lurking_swe 3y agomost routers let you set a primary dns server and a secondary. just set the secondary to something like google or cloud flare dns.
- smarkov 3y agoI believe this only works if your ad blocking DNS is configured to return 0.0.0.0 for all blocked domains rather than NXDOMAIN, since then services might try using the secondary DNS instead and that would result in nothing getting blocked. Ideally your secondary DNS should be a copy of the primary.
- vladgur 3y agodo you know if pihole or Adguard can configured to support confirming to the router or the client that resolution took place, rather than try the secondary DNS. If i understand you correctly, if you have a blocking internal DNS running pihole or Adguard and an external general DNS such as google or cloudflare, unless what you described can be configured, the requests that come back "blocked" from pihole would then simply be resolved by google/cloudflare, thus negating the point of pihole.
- 35mm 3y agoThose who are using DNS level ad blocking: how much do sites break? And how easy is it to unblock them? I currently use browser based blocking and find a lot of sites don’t work at all. Typically SPAs. But if I have to use them, I can disable the adblocker in two clicks. How does that compare?
- HumblyTossed 3y agoSites break often if they're shitty. Especially if you click Google's "Sponsored" link by accident after a search because I block Google's ad stuff. But, you get used to what sites break and decide if it is worth bothering to fix it or not. I can disable my pihole by opening a browser, navigating to pihole and disabling it.
- ololobus 3y agoI use PiHole, it does break some stuff here and there, and sometimes useful things like Private Relay or iCloud in iOS; or once YouTube history stopped working for me (apparently they use a separate domain to track watched videos and progress!). It also depends on the block lists you upload. It’s pretty easy to unblock, especially web, as you just look on which domain cannot resolve in the browser dev tools and add it to the allow list. Yet, DNS-based blockers have a limited usefulness at this moment as some major ad-providers started using the same primary domain for serving ads. For example, YouTube, partially Google, Yandex. I guess they cover everything with top level load-balancer and then route internally to specific service ingresses
- lock-the-spock 3y agoI use AdGuard home as part of my HomeAssistant setup and have had no problem at all. Only thing is to turn off the enforced safe search as that quite reduces results.
- LeoPanthera 3y agoIt entirely depends on which blocklist(s) you use. I had to stop using the StevenBlack list because it started breaking a lot of things, apparently intentionally. I recommend using only one list, rather than a combination of several. I switched to the https://oisd.nl https://oisd.nl Big List, which has been great... although it did break GitHub yesterday. That was the first breakage since I switched, and it was fixed when I reported. But still, keeping an eye on it.
- dang 3y agoRelated: AdGuard Home: Network-wide ads and trackers blocking DNS server - https://news.ycombinator.com/item?id=33387678 https://news.ycombinator.com/item?id=33387678 - Oct 2022 (113 comments) Show HN: AdGuard Home – an open source network-wide ad blocker - https://news.ycombinator.com/item?id=18238503 https://news.ycombinator.com/item?id=18238503 - Oct 2018 (2 comments)
- readscore 3y agoI'm experienced in DNS but have never seen the point in DNS blocklists. It feels like the wrong layer. I do adblocking with a browser extension. The adblocking has more context, can modify the page, and has easy UI integration for debugging and turning it off. What else are DNS blocklists for? Clients except browsers? For the record, on my desktop I use systemd-resolved (for DNSSEC) and dnscrypt-proxy2 (for encryption). On my router I run unbound as recursive resolver for other devices. On my phone I use quad9, and adblocking via Firefox.
- Larrikin 3y agoI enjoy having ads blocked in apps and on my iPad, where ad blocking is extremely limited otherwise. If you look at the logs from your media box, (whether that is your TV, Roku, or whatever) there's a massive amount of tracking that gets sent up. Combined with Tail scale I can even block ads and tracking on my devices when I'm not home.
- readscore 3y agoThanks I understand now. All my devices are plain Linux distro machines, or Android.
- muppetman 3y agoAdblocking via the browser is the best option if it's available. All the games the kids play on their iPad try to insert ads, track them, all that sort of stuff and DNS based Adblocking stops that. My wife's iPhone isn't subject to ads when she's reading the news in Safari. On my Google Pixel I don't see ads in browsers either, Firefox I use uBlock but even the Google Newsfeed uses Chrome for webview, so DNS adblocking stops me having to see the sponsered stuff in there. There's so many places other than "the browser" to see ads, to even question that seems like not really having knowledge of what the Internet is used for in 2024. Edit: Sorry that's a bit rude, I just meant maybe you don't use it the same way a lot of others do. Sorry for sounding obnoxious and rude. DNS blocking doesn't stop stuff like ads in Instagram, or Youtueb etc, but it certainly helps in a lot of other situations like Ads in the Imgur app etc etc.
- seanieb 3y agoAdGuard is a Russian company, with Russian engineers, the majority of AdGuard developers and other employees working from Moscow, registered in Cyprus. Not a great recipe. Hard pass on security grounds.
- tills13 3y agoIt's open source you can verify it yourself.
- Sammi 3y agoGood luck with that.
- mrcarruthers 3y agoTechnically, yes you can. But do you really have the time to sit down to understand a piece of software enough to know if it's doing anything nefarious?
- modzu 3y agoand your macbook was built in china. uh oh
- seanieb 3y agoApple is an American company and we’re not actively paying for a hot war against China.
- hbcondo714 3y agoThere are a few mostly positive comments here about NextDNS but I'll start a new comment since I'm thinking about switching away from NextDNS. Why? I'm on a Mac / Safari now and would like to enable their "Hide IP address from trackers" feature but if I do, then I start seeing advertisements on websites that would normally be blocked by NextDNS. So I have to uncheck this option and can't use Apple's feature. Overall, I guess the two can't be used together, per an issue reported on the NextDNS Help site: https://help.nextdns.io/t/q6yq4xy/nextdns-stops-working-properly-when-updating-to-ios-17-ipados-17 https://help.nextdns.io/t/q6yq4xy/nextdns-stops-working-prop... Does anyone by chance know if this is a known issue with AdGuard or even Pi-hole?
- pseufaux 3y agoAre you referring to iCloud Private Relay? If so that's expected behavior for with any DNS based ad blocker. Turning on the relay proxies your connection and your local network's DNS server will not be used. Doesn't matter if it's PiHole, NextDNS, or AdGaurd.
- hbcondo714 3y agoThanks, I did not think of that but iCloud Private Relay requires an iCloud+ subscription[1] which I do not have. I'm referring to the "Limit IP Address Tracking" option[2] in Safari/iOS and "Hide IP address from trackers" option[3] in MacOS/Safari [1] https://support.apple.com/guide/icloud/set-up-icloud-private-relay-mm7dc25cb68f/icloud https://support.apple.com/guide/icloud/set-up-icloud-private... [2] https://support.apple.com/library/content/dam/edam/applecare/images/en_US/icloud/ios15-2-iphone-12-pro-settings-cellular-cellular-data-options-limit-ip-address-tracking.jpg https://support.apple.com/library/content/dam/edam/applecare... [3] https://appletoolbox.com/wp-content/uploads/2014/02/Hide-IP-Address-From-Trackers-Mac.jpg https://appletoolbox.com/wp-content/uploads/2014/02/Hide-IP-...
- _kb 3y agoIt does with encrypted DNS (I think - still mid setup). If you use a configuration profile [0] to explicitly set a DNS over HTTPS or DNS over TLS server this is still honoured within private relay. IMO vanilla private relay is much neater and simpler if privacy is your goal. It uses Oblivious DNS over HTTPS [1] which is pretty neat. To trade some of that privacy to reduce ads setting up encrypted DNS restores filtering control. This does mean you then need to funnel those queries somewhere likely less oblivious though. Current setup I'm playing with in the homelab uses Adguard Home for filtering. This then forwards to a local Unbound instance acting as a recursive resolver with strict DNSSEC [2] and QNAME minimisation [3]. End result is the DNS traffic is still open, but does not all go to any one single entity (apart from my ISP, which can see TLS SNI anyway). [0]: https://dns.notjakob.com https://dns.notjakob.com [1]: https://datatracker.ietf.org/doc/html/rfc9230 https://datatracker.ietf.org/doc/html/rfc9230 [2]: https://datatracker.ietf.org/doc/html/rfc7816 https://datatracker.ietf.org/doc/html/rfc7816 [3]: https://datatracker.ietf.org/doc/html/rfc9364 https://datatracker.ietf.org/doc/html/rfc9364
- jklinger410 3y agoI love the AdGuard plugin as compared to UBlock because it allows me to make a blacklist instead of a whitelist.
- NoPicklez 3y agoI swear there is a set time that HN can't go without a Pi-Hole or Adguard Home post.
- Brajeshwar 3y agoI’ve a bi-annually repeating task on my calendar -- HN: Pi-Hole / AdGuard? ;-)
- linuxandrew 3y agoI wonder how much DNS blocking would contribute to a unique browser fingerprint? Like a tracker could use a range of domains, some of which are known to be blocked by certain end-user software, to build a fingerprint. I currently use a vanilla LibreWolf which has uBlock Origin and reasonable defaults out of the box for this reason. My only other line of thinking is that a combination of DNS, IP and in-browser blocking could be more effective than just in-browser alone.
- NL807 3y agoHow effective is AdGuard against YouTube ads? Pi-Hole doesn't work as its filtering is at the DNS level, I suspect AdGuard has the same issues?
- Brajeshwar 3y agoAdGuard blocks at the client level, so it works (so far) as far as I tested in the last couple of weeks (with a non-premium account). Disclaimer: YouTube is still very affordable in India, our family subscribe to the YouTube Premium.
- vin047 3y agoDoesn’t work for YouTube ads – they no longer load ads via DNS and instead embed them directly into the video feed. Ublock origin via the browser is the best way to block them. If you wish to use a client app, best bet is to sideload a 3rd party app like like SmartTubeNext for Android TV or YTLitePlus for iOS.
- deleted 3y ago[deleted]
- Brajeshwar 3y agoI used Pi-Hole, then went to NextDNS, then to AdGuard DNS, tinkered with AdGuard Home, and currently testing Control-D. They are all actually pretty good, similar features, and it has become just a matter of personal choice. In all fairness, when I have some time and can invest in decent hardwares, I might go back to AdGuard Home with one of the paid services as backup for travel, and for the other family members. Pi-Hole works really well but once-a-while, when I'm traveling, it will decide to act up and it's a whole IT support with the family over phone for minutes if not hours. I'm not smart enough to setup a secure enough tunnel and the like, and haven't read up enough on the topic. This follows similar pattern with AdGuard Home. NextDNS, AdGuard DNS, Control-D are easy and just works, especially with the devices that the family uses. I think I bought one of those AdGuard Lifetime license, so I use that to block client-side rendered ads in conjunction with either AdGuard DNS or NextDNS or Control-D. Right now, Control-D is doing pretty good with my test-drive. Edit: The other reason is that many websites such as the Governments’, Banks (at-least in India) seldom works with Pi-Hole or AdGuard Home. With the other tools, I can turn off for a while, and go Internet-Naked and do the transactions, pay the insurance, etc. https://adguard-dns.io https://adguard-dns.io https://nextdns.io https://nextdns.io https://controld.com https://controld.com