18 ms·
Pi-hole v6
- Mossy9 2y agoPi-hole is such a great tool. I've been running it for a few years on a raspberry pi zero, and am constantly astonished by the sheer amount of cruft it blocks for me. Congratulations to the team for the release - happy to support you via Patreon!
- hk1337 2y agoI have had many times click an article link on reddit where everyone in the post comments complains about how the site is riddled with ads that it makes it unreadable and all I see is the article with a lot of whitespace.
- martin_a 2y agoIT department does not like that, but I had them install Firefox on the machines of my team, so we can install uBlock Origin. People are _amazed_ how the internet does look without ads.
- ed_mercer 2y agoCan’t you just use uBlock for this?
- saltymug76 2y agoPihole catches a lot of the trackers and crap coming out of my android tv. On my pc I see it as an extra line of defense after ublock.
- mistyvales 2y agoHulu stopped working properly on my Shield after using Pi-Hole, so I guess it was working?
- saltymug76 2y agoOn the pihole subreddit there's a wiki with lists of domains you can whitelist for certain services. I had to whitelist something for xbox live to work.
- dmajor2 2y agoYeah, even the paid (non-ad) hulu has trouble if you block its telemetry servers.
- alimbada 2y agoYou can't use uBlock everywhere, .e.g phones, tablets, TVs.
- deleted 2y ago[deleted]
- unsnap_biceps 2y agoDoes anyone know if pihole is ever going to add DoH or similar support natively? I've had such troubles with cloudflared awhile back that I gave up on DoH, but would love to encrypt those queries.
- zamubafoo 2y agoI've been using https://github.com/DNSCrypt/doh-server https://github.com/DNSCrypt/doh-server for serving my DNS server via DOH for at least 2 years. Only had two issues with it and both were due to lack of maintenance on my part (ie. not updating the binary for one and then not re-configuring it after I changed configurations for the upstream DNS).
- hotpocket777 2y agoAssuming doh = dns over http
- unsnap_biceps 2y agoYes
- chgs 2y agoI’m not sure why I’d ever want DoH, I block as much as I can at my firewall and have a canary domain. I want my devices to use my defined dns sever on my network, not some ad company (and all tech companies eventually become ad companies)
- unsnap_biceps 2y agoI want pihole to talk encrypted to the upstream dns server. I don't actually care if my devices talk encrypted to pihole. I just don't want to leak dns requests to my isp. If there's a way to do this without DoH or DoT, I'd happily learn more about it.
- bjoli 2y agoDoT has a standard port, meaning blocking (conforming) requests simple. DoH uses 443. Nothing says clients need to confirm to the port requirements, but most companies will be lazy and assume 853 will work.
- eamag 2y agoWant to highlight https://nextdns.io/ https://nextdns.io/ as a similar service, very happy with it
- poisonborz 2y agoPihole being a self-hosted service and this being a third party one, I would say the target group is somewhat different.
- whalesalad 2y agoit's more than that - an app running on your internal network is going to have way better latency than nextdns
- zufallsheld 2y agoHowever you can't use it on the phone while not at home (aside from using vpn/wireguard), but nextdns allows it. As for the latency - is it really noticeable?
- uncharted9 2y agomy biggest gripe with NextDNS is not having an ability to add custom blocklists. I'd gladly pay for it even if there was a paid tier with this feature.
- zufallsheld 2y agoIt seems you can add domains to the deny list via their api: https://nextdns.github.io/api/#profiles https://nextdns.github.io/api/#profiles So atleast there's that.
- uncharted9 2y agoI'm aware of adding domains one by one, but I want to add some lists like Hagezi Threat Intelligence Feed which is not available in the blocklists, and these blocklists have >500k domain list. I'm currently using Blocky as my DNS resolver. It works fine and is super fast because of the fine control over caching, but I'm disappointed with its memory footprint. 400MB for a total blocklist of 1.3M domains
- LeoPanthera 2y agoI've been using AdGuard Home, which does pretty much the same thing, but is slightly better polished, with things like support for DoH and OSs other than Linux. https://github.com/AdguardTeam/AdGuardHome https://github.com/AdguardTeam/AdGuardHome
- lawn 2y agoI even run Adguard Home on my router that runs opnsense.
- samplatt 2y agoWhat routers are compatible with opnsense? Or does it need a full-blown server/container? Been happy with my pihole for a few years, and this thread is full of new information for me.
- gh02t 2y agoOpnsense is not like OpenWRT, it targets running on relatively powerful generic x86 hardware. Intel CPUs and networking hardware usually works best because of driver support on BSD, but it will work on others. I say "relatively" because even low power old embedded CPUs are more than enough to route at a gigabit or more with lots of firewall rules and services running. Opnsense's cousin Pfsense also has some support for ARM, but that version is only really available on their commercially supported hardware. Most people either buy a generic box that can be had for ~$250, or recycle an old PC and stick in a network card. You can also buy commercially supported hardware for Opnsense or Pfsense's parent companies, though the value proposition isn't worth it for home users IMO as you will pay a steep premium versus loading up something yourself.
- samplatt 2y agoThanks very much for that. Been thinking about converting an old server to a router + container host for a while.
- bangaladore 2y agoIronically their website has been hugged to death.
- piyuv 2y agoWhy is it ironic? They’re not providing load balancing or anything similar
- bangaladore 2y agoSorry if the point wasn't clear. The service/device dedicated to killing connections (blocking dns, whatever) can't/won't serve my connection.
- antonvs 2y agoYou should let Alanis Morissette know.
- NeckBeardPrince 2y agoI don't think you know what irony means.
- bangaladore 2y agoMaybe you'd better define it as an "amusing twist".
- triyambakam 2y agoAt this point we should accept the vernacular use of the word as correct.
- zymhan 2y ago> The web interface has been completely overhauled with settings split into Basic and Expert modes. This allows users to customize their experience based on their comfort level and needs. This sounds helpful for setting up a Pi-Hole for family or friends that aren't DNS admins by day.
- _fat_santa 2y agoPi-hole is a killer application and I've loved it since I got it setup. One other app I highly recommend to run on your Pi in addition to Pi-hole is Nginx Proxy Manager[1]. [1]: https://nginxproxymanager.com/ https://nginxproxymanager.com/
- kmfrk 2y agoLots of great memories using Pi-hole and messing with RPi. I eventually ended up putting my devices on Tailscale and managing DNS through it, eventually using Mullvad VPN as the exit node. Pretty good interface, and most people just have to connect using the app. Having a virtual network between devices with dedicated IPs is pretty nice too.
- andy_xor_andrew 2y agoI set up pi-hole recently after hearing about it for years. I was kind of surprised at a lack of really basic features (imo): There isn't any kind of "dry run" or "phantom" mode, where requests are not actually blocked, but appear marked in the log UI as "would be blocked". This is super important because I want to see all the things my home network is doing that would be blocked before I actually hit the big red button. I want to fix up the allow/denylist before going live. It's also not possible (or not clear) how to have different behavior for different clients. For my "smart tv" which I begrudgingly have to allow on my network occasionally for software updates, I want to treat it with the strictest possible list. But for my phone, I don't want that same list. There's a concept of "groups" so perhaps this is user error on my part, but the UI does not make this clear.
- jkingsman 2y agoI think log-don't-enforce and per-client block profiles are probably basic to people who work with networking regularly, but are probably pretty far out of reach for the average home user who are probably needing to expand their networking knowledge just to distribute custom DNS via DHCP. So, I agree that those would be lovely features but are, I think, a ways beyond what I would assume the p90 of pihole users would need or be able to use.
- bdcp 2y agoFor the seconds question, it is indeed Groups. I have my SO's phone bypass everything. It's the way she wants it. Yea i agree it's not super UX friendly.
- ge96 2y agoI think I'll never buy a smart TV what an ultimate ahole move to put ads in there. It's like the Kindles where you have to read these ads before you can open your book (of course you can pay a 1-time fee). Like buying a movie on YouTube and having to watch ads in it or can't see full res unless you're on an allowed device. If UBO actually stops working on Chrome I'll either leave or use pihole. My cheap android phone installs games by itself eg. candy crush ugh. My own fault I get it buy a $2K phone instead of $160
- kayson 2y agoI wish pfblocker-ng was as easy to use and polished as pihole. It seems silly to run an extra DNS resolver if I'm already running one on pfsense, but the interface makes it tempting
- jedisct1 2y agoI just use dnscrypt-proxy directly.
- seanp2k2 2y agoI’ve been happy with AdGuard Home on two Pi4s and a little home server for years now: https://adguard.com/en/adguard-home/overview.html https://adguard.com/en/adguard-home/overview.html I have some scripts to sync config between them and a Jenkins job if I want to pause blocking on them for a bit. It looks like https://github.com/mattwebbio/orbital-sync https://github.com/mattwebbio/orbital-sync and https://github.com/lovelaze/nebula-sync https://github.com/lovelaze/nebula-sync can sync configs with Pi-hole 6 now, but it’s quite a bit of code for what looks like just a few HTTP requests to get the config from one using the teleporter feature, then restore it on the others using the same.
- seemaze 2y agoA Raspberry Pi with Alpine Linux makes a sweet little DNS server. AdGuard Home is even packaged in the testing branch[0] these days [0] https://pkgs.alpinelinux.org/packages?name=adguardhome&arch= https://pkgs.alpinelinux.org/packages?name=adguardhome&arch=
- plg 2y agolove pi-hole we block all meta and X properties from our home network, also ads and it's self hosted on our own metal it's a wonderful life
- andrewinardeer 2y ago> we block all meta and X properties from our home network, also ads There's a difference between meta, X and ads?
- google234123 2y agoGood way to teach other members of your house to use VPNs to bypass your censorship regime
- sciencerobot 2y agometa and X are both heavily censored so I guess it's censors all the way down?
- corey_moncure 2y agoI'd like to hear more about this. Can you provide an example of censorship on X?
- xrisk 2y agohttps://en.wikipedia.org/wiki/Twitter_suspensions https://en.wikipedia.org/wiki/Twitter_suspensions
- corey_moncure 2y agoLet me put it another way; can you provide some examples of ideas, topics or opinions that I are likely to be censored if I posted them on X?
- 2y ago
- jccalhoun 2y agoI've been using Technitium for a couple years and been pretty happy with it https://technitium.com/dns/ https://technitium.com/dns/
- bjoli 2y agoSo have I. I found it more approachable once I started having more advanced configurations.
- malmeloo 2y agoTechnitium is great. Rock solid, plenty performant and it has more features than you'll ever need. Pretty wild when you consider it's being maintained by a single dev.
- JamesBrooks 2y agoI moved from pihole to Technitium a few months back because I wanted more DNS features than just adding A and CNAME records. For example the split horizon features to return different responses to DNS queries depending if I'm connected to my Tailscale network or not has been pretty slick. I documented that process here in case anyone is interested: https://blog.jamesbrooks.net/posts/technitium-dns-server-with-tailscale/ https://blog.jamesbrooks.net/posts/technitium-dns-server-wit...
- tailspin2019 2y agoExcellent write-up. As a Tailscale + Pi-hole user you may have just inspired me to switch to Technitium. I’ve wanted that kind of split horizon functionality for years, for all sorts of things!
- 2bluesc 2y agoSwitched to Technitium (from piHole via Docker on amd64 and manual dnsmasq before that) primarily for DNS over HTTPS and never looked back. Used it for DHCP and DNS.
- ConanRus 2y agoWe’ve integrated a new REST API and embedded web server directly into the pihole-FTL binary. This eliminates the need for lighttpd and PHP" oh noes!
- ncrmro 2y agoNice. I wish pihole or adguard would add support for change DNS records based on the query subnet. I believe this is called DNS views. That way my local devices and wireguard devices can get the correct IP for internal services.
- VTimofeenko 2y agoIn unbound those are indeed views[1]. I moved from pihole to unbound+nsd a couple of years ago for precisely this use case. Block filters courtesy of[2]. [1]: https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering/tags-views.html https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering... [2]: https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts
- Marsymars 2y agoI managed this by getting a gTLD (digit-only .xyz is cheapest) for internal-only services and then running a Caddy instance to reverse-proxy to my internal services. I don't port forward or open ports to that Caddy instance, so it's not available externally.
- dpacmittal 2y agoWith ddwrt and adguard, it took a while to setup but I can ping all my devices with <hostname>.lan.
- unethical_ban 2y agoSlightly off topic, but it annoys me that protonvpn does not allow split tunnel of DNS to an internal host. It calls this DNS leak protection, which is a good default. But I want to run my own DNS server and I know what I'm doing, and the Proton GUI won't let me.
- aspenmayer 2y agoThe GUI app should have a custom DNS option: https://protonvpn.com/support/custom-dns https://protonvpn.com/support/custom-dns
- unethical_ban 2y agoI am almost certain that in my previous testing, internal DNS addresses still didn't work. Their "leak protection" blocks it.
- miningape 2y agoHa! I bought a Pi5 as a Christmas present for myself, I've only done some basic setup and gotten sidetracked by other projects - but setting up pi-hole is near the top of my list of sh*t to get done
- edm0nd 2y agoIt's suuuper easy to setup pihole on it. Takes literally 1 curl request and then like 3 minutes.
- RandomDistort 2y agoNot sure if this is the right place to ask, but I've got a semi-obscure DNS question. I'd like to use Cloudflare's Zero Trust DNS filtering with DoH by running a DNS proxy on my network. I can get this to work great with github.com/adguardTeam/dnsproxy (running on a Pi 4B) but what I would really like is to have different devices (based on their IP on the network) get their queries forwarded onto a different DoH upstream. Is this possible in a simple way?
- woleium 2y agoPerplexity thinks so: https://www.perplexity.ai/search/i-d-like-to-use-cloudflare-s-z-TNlcaKyTR2OPgllCqoRq_g https://www.perplexity.ai/search/i-d-like-to-use-cloudflare-...
- LeoPanthera 2y agoPlease don't use AI to write your comments. If I wanted to know what AI thinks I could ask it myself. I read the comments to get feedback from humans. Edit: OP edited their comment, was previously a very long AI-generated response.
- woleium 2y agoNoted, won’t do it again :)
- Etheryte 2y agoPlease don't spam HN with LLM generated slop. The value of HN is the human discussion, everyone here is perfectly capable of asking an LLM of their choice.
- deleted 2y ago[deleted]
- wkyleg 2y agoIn my experience Pi hole is a very worthwhile investment. People who used my internet when I had one would remark how much faster it was. Everything in general seems faster, even things that you wouldn't think of. I typically use Brave for browsing which has good ad blocking capabilities, but this adds a whole additional layer. The only reason I don't use one now is that I travel a lot more so it's irrelevant, and I have to work enough on tools with Google/Vercel/other analytics that it is just very inconvenient. Regarding smart TVs, I have found that it's better to just use an Apple TV or Kodi box and never connect to them internet though. Having said, I gave my TV away because I never used it, so this might not be as up to date. A Pi hole will block ads on smart TVs though.
- _chris_ 2y agoWouldn’t a smart tv do something ... smarter than just using the default dns given to it by the network? I’m not up to speed on this stuff but I thought pihole only blocked the simplest stuff from devices that play nice?
- dark-star 2y ago> Wouldn’t a smart tv do something ... smarter than just using the default dns given to it by the network? It could certainly try... but usually you would block that in your firewall. Fixed DNS servers or fixed server IP addresses are tricky because if you ever need to change them, you can't, because you'd need to update the hardware (which you can't since it sits behind a firewall). It could try to use things like Google's DNS server, but that is easily blocked in your router. Not a lot that could be done except trusting your (internal) DNS server...
- netsharc 2y agoWhy should the programmers of the TV's OS look for edge cases, and do you think the TV makers would give them budget for that? For 90+% of users the standard config of trusting the DHCP server will work fine, and the Pi-Hole users will probably not give them money anyway, and will be dedicated to defeat their workarounds...
- 2y ago
- mrbluecoat 2y ago5+ year development cycle. Impressive! https://pi-hole.net/blog/2023/10/09/pi-hole-v6-beta-testing/ https://pi-hole.net/blog/2023/10/09/pi-hole-v6-beta-testing/ Any details on what HTTPS support provides, other than a TLS connection to the admin dashboard?
- thomassmith65 2y agoThat works for me. It means I don't need to relearn everything every year, and the major versions probably won't be riddled with bugs.
- Sohcahtoa82 2y agoI love PiHole. I run my PiHole on a small cloud VM that I use for several projects, but put it behind a VPN that's configured to only forward DNS lookups, then VPN into it from my phone. So many advantages behind this setup. - Since only DNS lookups are tunneled, I don't have to worry about tunneling ALL my traffic and paying egress fees - Blocks ads in ALL apps, not just my browser - If it's acting up, I can just disconnect from the VPN to disable PiHoling - Don't have to expose my home IP address and open a port for the world to start banging on
- TheArcane 2y ago> Don't have to expose my home IP address and open a port for the world to start banging on Is that really an issue if all you're exposing is the VPN port? Wireguard for instance has industrial-grade encryption. Even open port 51820 should be fine
- Sohcahtoa82 2y agoI mean, probably not. But I like the idea of keeping everything closed anyways.
- 8fingerlouie 2y agoWith wireguard in particular, you're probably not running much risk, as wireguard runs over UDP, and as long as you're not connecting with a correct (recognized) key, it will not even generate a response, so a potential attacker has no way of knowing for sure that wireguard is running on a given port.
- lanthade 2y agoThe big feature miss for me in this announcement is baked in support for configuration sync between servers. Redundant DNS is common and it would be nice if pi-hole supported this oob. Making it even better would be an ability to see stats across all synced servers from one location.
- reboot81 2y agoI’m using https://github.com/ShiromMakkad/docker-pihole-sync https://github.com/ShiromMakkad/docker-pihole-sync To sync my two piholes. But I haven’t figured out how to keep my third pihole (ip-failover) to get in the loop…
- undersuit 2y agoI'm using https://github.com/vmstan/gravity-sync https://github.com/vmstan/gravity-sync to sync my three piholes but I'll need to find a replacement if I upgrade to pihole v6.
- TriangleEdge 2y agoI have a script update my hosts file to route domains to 0.0.0.0 and ::0 . I get the domains from https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts.
- precommunicator 2y agoThe point of pihole is setup blocking on multiple devices though, some of them which you don't control like your PC e.g. smart tvs
- nirav72 2y agoStill no wildcard domain support for local DNS.
- Netcob 2y agoFinally a REST API! I've been waiting for this - I wanted to play around with blocking distractions on various rules, but controlling pi-hole remotely was a huge pain and often didn't work until now.
- nirav72 2y agoHave they added more to the existing API? They already had an http API to enable/disable blocking.
- Netcob 2y agoThe admin API wasn't really official - at least I couldn't find documentation anywhere and had to piece it together from the source code. And regex filters didn't seem to work through that - didn't get an error back, but nothing changed either.
- mbasho 2y ago[dead]
- issafram 2y agoFINALLY. that dev branch was out there forever
- merillecuz56 2y ago[flagged]
- peme969 2y agonoice
- eellpp 2y agoHave used pi hole for over 5 years and very happy with it. Most times I use it via phone to manage kids devices to block/unblock access etc and this also works quite well . Thank you very much
- sizzle 2y agoWill it block YouTube ads?
- 10729287 2y agoShort answer : no.
- ProllyInfamous 2y agoI've had the same PiHole rule (for years!) which blocks all the text-splash-over-ads... but it becomes very cat and mouse if you want to block the pre-roll video ads (any rule that initial works... won't for very long). Instead, use yout-ube.com [insert a hyphen into any URL] and ALL ads disappear.
- TZVdosOWs3kZHus 2y agoCame here to give a big THANK YOU to everyone making this project possible. I am using Pi-Hole for about 8 years and can't imagine a world without it. Another big THANK YOU to all list maintainers out there. You're doing an incredibly useful service to the community.
- tailspin2019 2y agoSeconded! I’ve been using it for multiple years and it is extremely good, and reliable. There are always some features that I wish it had, but ultimately it does a really good job. It’s easy to take for granted the hard work that goes into creating and maintaining such awesome tools.
- dmacvicar 2y agoI do something similar to Pi-Hole using plain dnsmasq. I use two old PINE64 (one with FreeBSD, one NetBSD to make it more fun), and the Ansible configuration downloads https://github.com/ShadowWhisperer/BlockLists https://github.com/ShadowWhisperer/BlockLists and creates a file dnsmasq can use. Which lists from the repo to use is defined as a variable. Works very well and I feel I can understand what is going on.
- opengears 2y agoif you are on openwrt i can recommend checking out unbound and adblock as alternatives (running directlly on your routers without the need of a raspberry pi)
- urbanporcupine 2y agoI am a beginner and never used Pi-Hole before. I checked that Pi-Hole can run on Raspberry pi zero as per the GitHub. But would you recommend to use Raspberry Pi 5 2 GB or 4 GB RAM instead of Raspberry Pi zero. I don't have any Raspberry Pi and I intend to make a new purchase.
- theshrike79 2y agoThe 5 is completely overpowered and overpriced to run Pi-hole. Go with the zero instead.
- Havoc 2y agoCan it do native dns over http yet? Without hacky unbound proxy I mean. That’s why I switched to affairs home but wouldn’t mind switching back
- ProllyInfamous 2y agoI make these suggestion during all conversations about PiHoles: Use Class A2 SDmicro cards (they'll last significantly longer... particularly if you keep logs). There are additional 3rd-party installations which can write into RAM, but IMHO it's easier for most new users to just buy better NANDs. Set up more than one physical Raspberry Pi, running multiple versions of PiHole software on multiple IP addresses. Have your main DHCP router auto-issue DNS information for your "most permissive" PiHole, with a minimal list of choice URL-blocks (e.g. pagead2.* , doubleclick). Individual clients can then manually change DNS server to 2nd (3rd... 4th...) PiHole(s) which are each more-restrictive. This allows non-technical users to still browse somewhat ad-free, but also won't block banking/govt/etc for novices. As a failsafe, teach users to enter your router's IP as DNS x.x.x.1 [should they ever need to bypass local filtering, entirely]. I use sequential IP addresses [192.168.0.6, x.x.x.7, x.x.x.8, x.x.x.9] so it's easier to explain/teach my networks ad-blocking capabilities. YES, I understand that Pi-Hole allows different clients to follow different rulesets, but if you can afford to buy redundant hardware it's just so much easier to change the client DNS server information when a specific website isn't working correctly [due to erroneously blocked host].