5 ms·
Use and Configure Pi-Hole[0] [0]:https://jeffmorhous.com/block-ads-for-your-entire-network-with-a-raspberry-pi/ https://jeffmorhous.com/block-ads-for-your-enti
by TechDebtDevin 2y ago
Use and Configure Pi-Hole[0]
[0]:https://jeffmorhous.com/block-ads-for-your-entire-network-with-a-raspberry-pi/ https://jeffmorhous.com/block-ads-for-your-entire-network-wi...
Also a video for those more YT inclined: https://www.youtube.com/watch?v=eCA24qJBG8Q https://www.youtube.com/watch?v=eCA24qJBG8Q
- nickburns 2y agoThis does nothing for a mobile device that either concurrently maintains its cellular 'data' connection together with its Wi-Fi connection (and whose apps are permitted to access both)—or leaves the LAN without connecting remotely via a force-tunneled VPN. And even with such a VPN, the cellular NIC continues to maintain baked-in alternate routes on both Android and iOS. All that's before we even get into specific Pi-Hole and LAN config, not to mention DoH. Krebs and everyone else he cites is right—it's time for Apple and Google to eliminate MAID altogether. ETA: Do not downvote this parent! Use trustworthy ad blockers anywhere and everywhere you can!
- samename 2y agoNextDNS is a great alternative for mobile devices https://nextdns.io https://nextdns.io
- squaresmile 2y agoIf self-host is your thing, there are blocky [0] or Adguard Home [1]. I self-host DOH using blocky so my Android devices can use it via "Private DNS" that is active on both wifi and cellular. [0] https://0xerr0r.github.io/blocky/latest/ https://0xerr0r.github.io/blocky/latest/ [1] https://github.com/AdguardTeam/AdGuardHome https://github.com/AdguardTeam/AdGuardHome [2] https://adguard-dns.io/en/public-dns.html https://adguard-dns.io/en/public-dns.html how to configure
- nyarlathotep_ 2y ago> the cellular NIC continues to maintain baked-in alternate routes on both Android and iOS How do you know this is the case? (I believe it to be, would like to verify) Also worth mentioning many apps hardcode DNS servers or fallback to other DNS providers when they fail to resolve hostnames. I see this all the time on my network. (I have a PfSense box that redirects to upstream NextDNS when this happens)
- autoexec 2y agoDoH/DoT along with hardcoded IPs make DNS ad blocking impossible.
- switch007 2y agoAnd TLS. Sure it stops lots of other bad things, but it is quite the blocker to doing content filtering of the page contents.
- TechDebtDevin 2y agoDo you know of any blogs/articles I can read more on this?
- autoexec 2y agohttps://ericlathrop.com/2021/03/dns-over-tls-lets-google-serve-you-more-ads/ https://ericlathrop.com/2021/03/dns-over-tls-lets-google-ser... It isn't just people using DNS filtering for ads that have this problem. Network admins at companies face the same problem (see for example https://cleanbrowsing.org/help/docs/block-dns-filtering-evasion-technique-local-dns-changes-doh-vpn/ https://cleanbrowsing.org/help/docs/block-dns-filtering-evas...) Some browsers, apps, or devices might let you disable DoS/DoT or might let you configure it to use your own DNS server, but none of them have to let you and even when they give you that option they can still do whatever want (https://discourse.pi-hole.net/t/chromium-bypasses-pi-hole-by-tunneling-via-doh-solution-is-to-block-dns-google/71330 https://discourse.pi-hole.net/t/chromium-bypasses-pi-hole-by...) Obviously any application or device using a hardcoded IP address will bypass DNS entirely so DNS filtering isn't going to work. See https://old.reddit.com/r/pihole/comments/djacup/im_starting_a_list_of_hardcoded_dns_abusers_reply/ https://old.reddit.com/r/pihole/comments/djacup/im_starting_...
- mixmastamyk 2y agoJust because it doesn’t work all the time doesn’t mean it never does. Defense in depth. One aspect is to use trustworthy software, not written by an advertising company.
- 2y ago