Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lightswitch05
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
lightswitch05
6y ago
The pihole is nice, but isn’t a silver bullet. I have a roku tv, I hate it, but I think I hate it less then I would hate another smart tv like Samsung or LG. No cameras or built in microphone- although the remote does have a microphone, but
32.
▲
by
lightswitch05
6y ago
This is the most simple setup I could get. https://github.com/lightswitch05/wireguard-docker
33.
▲
by
lightswitch05
6y ago
I agree, I have a little tool called `php-version-audit` that literally becomes useless after a few weeks without an update (you can't audit your php version without the knowledge of the latest CVEs). I have manually cleaned up old ima
34.
▲
by
lightswitch05
6y ago
Incorrect. Plausible has been blocked in my list since April 8th, including custom.plausible.io: https://github.com/lightswitch05/hosts/commit/21fd108ffd2996...
35.
▲
by
lightswitch05
6y ago
Thank you for the info, I'm sorry I misrepresented your project. For some reason I thought you had to enable advanced settings. Thanks for everything you do with uBlock Origin and uBLock Matrix. uBlock Matrix is one my the primary tool
36.
▲
by
lightswitch05
6y ago
So, the domain in question is ms.markosaric.com. Which is a CNAME to custom.plausible.io. uBlock Origin is able to block based on CNAMEs, but it is not a default configuration. PiHole V5 blocks based on CNAME as well, and it is actually ena
37.
▲
by
lightswitch05
6y ago
Looks like my lists are intended to be included, but it was linking to the raw Github source instead of the hosted Github pages version. I went through a major refactor 21 days ago that moved my sources lists around a bit - but preserved th
38.
▲
by
lightswitch05
6y ago
Yes, that is even better! Unfortunately it doesn’t work on iOS, or I would have never created my list. Literally the only thing I miss about Android was being able to use browser extensions like uBlock Origin with Firefox on Android. Safari
39.
▲
by
lightswitch05
6y ago
Yes, as you say, Integrity is preserved. However, Confidentiality is also another important aspect of Information Security. Making a 3rd party appear as a 1st party, is a privacy and confidentiality violation, which is why I do not like AMP
40.
▲
by
lightswitch05
6y ago
I'm glad you like it! If you have any issues with it, I encourage people to come open a ticket explaining what is wrong. Sometimes I screw up and block things that shouldn't be - other times I have reasons why I blocked something
41.
▲
by
lightswitch05
6y ago
I couldn't agree more that AMP is terrible. I do everything I can to avoid it. Using DuckDuckGo certainly helps, but I will still occasionally stumble on an AMP site. I've created a hosts block list to help me avoid AMP as much as
42.
▲
by
lightswitch05
6y ago
I had no idea about that config, but I've seen the behavior before. That behavior is even more interesting considering that Firefox will hide the 'www' subdomain in the URL[1]. So not only will it silently add the www, but it
43.
▲
by
lightswitch05
6y ago
That was a fascinating write-up! I too immediately looked for `domain.name` registration and would have marked it up to DNS trickery after that gave a NXDOMAIN. I'm glad you followed the rabbit down the hole on this one. I've adde
44.
▲
by
lightswitch05
7y ago
Pihole uses a forked version of dnsmasq they named 'Pi-hole FTL engine'. I don't believe there are any features of dnsmasq that cannot be used with the PiHole - but how to configure it to work alongside of PiHole might not be
45.
▲
by
lightswitch05
7y ago
It is resource inefficient, which is why PiHole supports it, but does not allow you to subscribe to list containing regex, as that would quickly make it unusable. I'm not sure how Dnsmasqs would be accomplishing this feature without so
46.
▲
by
lightswitch05
7y ago
Pi-Hole does support regex and wildcard based blocking
47.
▲
by
lightswitch05
7y ago
I maintain a hosts-formatted blacklist for all Facebook owned services, like Facebook and Instagram. Combined with a PiHole, its a fairly effective way to reduce tracking exposure to Facebook. https://www.github.developerdan.com&
48.
▲
by
lightswitch05
7y ago
I took a look the domains being used for the consent and saw an interesting JavaScript name: 'messagingWithoutDetection.js'. Looking into it more, I found the documentation [1], there is this disgusting paragraph: > The Dialogu
49.
▲
by
lightswitch05
7y ago
> I assume that by default certbot only checks the expiration date of local certificates against the system clock, it doesn't ping any external resources so it can't be aware that the certificate might have been revoked even th
50.
▲
by
lightswitch05
7y ago
Thanks for sharing! Also `fonts.gstatic.com` is a CNAME alias for `gstaticadssl.l.google.com` which is commonly blocked by ad blockers. uBlock Origin recently added CNAME based blocking, and PiHole is rolling out support for it too. Just an
51.
▲
by
lightswitch05
7y ago
What are your thoughts about it being an open source extension?
52.
▲
by
lightswitch05
7y ago
I've been using this extension for a couple years now. In fact, I submitted the pull request for the fbclid feature [1]. @Smile4ever merged and released the change the next day. It is a really great extension with a responsive and help
53.
▲
by
lightswitch05
7y ago
Ah, I took this quiz on my iPhone, luckily my pihole caught the trackers. I have a pretty extensive hosts list I use with the PiHole (full story included): https://www.github.developerdan.com/hosts/
54.
▲
by
lightswitch05
7y ago
I don't think anyone would make the argument that a PiHole is a replacement for following best practices in terms of computer and network security. I'm just pointing out that a PiHole can block google analytics and other common vi
55.
▲
by
lightswitch05
7y ago
This is just one of many reasons to use StevenBlack's Hosts [1] list to block this type of behavior. While it doesn't currently block link.wacom.com, it would have prevented the subsequent requests google analytics. It works even
56.
▲
by
lightswitch05
7y ago
I wrote PHP Version Audit to automatically keep track of PHP patches, particularly for releases that fix CVEs. This morning it automatically updated to include new CVE patches and releases: 7.4.1, 7.3.13, 7.2.26. This was the test to determ
57.
▲
Show HN: PHP Version Audit – Audit Your PHP Version for Known CVEs and Patches
(github.com)
8 points
by
lightswitch05
7y ago
|
1 comments
58.
▲
by
lightswitch05
7y ago
No problem, there is a FAQ on it: https://discourse.pi-hole.net/t/how-do-i-add-additional-bloc...
59.
▲
by
lightswitch05
7y ago
I agree that blocking OCSP (Online Certificate Status Protocol) servers is a bad practice. The argument to block them is that they can be used for tracking purposes. OCSP stapling is a great way to use OCSP without the risk of tracking - bu
60.
▲
by
lightswitch05
7y ago
If you are looking for more blocklists, I maintain several. I recommend my 'Ads & Tracking' list for most people. I also have an aggressive list - which I don't normally recommend. I also have a Google AMP list and a Face
More ›