Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rndomsrmn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
rndomsrmn
6y ago
Websites that use CNAME to forward their main domain to some tracking company, basically give their entire domain away, I don't see how that is a good secure way to track your users.. DNSCrypt-proxy (and even pihole these days I believ
2.
▲
by
rndomsrmn
6y ago
https://github.com/notracking/hosts-blocklists Use this for network wide blocking of all sorts of virtual garbage. Not only for safari, but all your locally connected devices.
3.
▲
by
rndomsrmn
6y ago
You can get even better coverage with the NoTracking lists (dnsmasq/unbound or dnscrypt-proxy) https://github.com/notracking/hosts-blocklists They focus not only on tracking but also malware prevention, where poss
4.
▲
by
rndomsrmn
6y ago
You might want to consider checking for hosts listed in https://github.com/notracking/hosts-blocklists This is an excellent merged blocklist, with public whitelist (oisd is fully closed, no insight in what is whitelist
5.
▲
by
rndomsrmn
6y ago
Also a ref to: https://github.com/notracking/hosts-blocklists They have a public whitelist and updates are pushed on a daily basis.
6.
▲
by
rndomsrmn
6y ago
See: https://github.com/notracking/hosts-blocklists#dns-over-http... how Mozilla deals with this. For Chrome this feature seems not to be implemented, making it harder to control your DNS behavior in your own network.
7.
▲
by
rndomsrmn
7y ago
It is possible to use this feature 'in' Pi-Hole, see: https://github.com/notracking/hosts-blocklists/wiki/Install-...
8.
▲
by
rndomsrmn
7y ago
Dnsmasq 'address=' function is just a substr() call, which is as fast as 'normal' hostname blocking (host == "adhost.com"). No regex magic is required there. You are not able to block something like 'ads.%
9.
▲
by
rndomsrmn
7y ago
regex is _extremely_ resource inefficient and should not be used with large sets of rules. Dnsmasqs domain redirecting feature (address=/adhost.com/#) is not supported by pihole. Is there any other way to wildcard block full domai
10.
▲
by
rndomsrmn
7y ago
dnscrypt-proxy is already supporting CNAME blocking and full domain based blocking (*.adhost.com), something that is still missing in Pi-Hole.
11.
▲
by
rndomsrmn
7y ago
A dnscrypt-proxy setup with https://github.com/notracking/hosts-blocklists/tree/master/d... goes a long way! For anything that is not blockable on DNS level one should use uBlock Origin from Gorhill.
12.
▲
by
rndomsrmn
7y ago
try hosting your own dnscrypt-proxy in combination with https://github.com/notracking/hosts-blocklists . That will turn off most trackers on your entire network.
13.
▲
by
rndomsrmn
7y ago
You will know on forehand what the fixed DOH servers will be, how else would you be able to locate them? If for example they will use the 1.1.1.1 DOH instance, you can simply redirect all localnet 1.1.1.1 (80/53) traffic to your own lo
14.
▲
by
rndomsrmn
7y ago
uBlock and uMatrix are a perfect addition to a setup with a dns based filtering system, though by themselves alone do not provide a solution for all use cases. Think smarttv's, consoles, IOS devices, apps, etc. Basically anything that
15.
▲
by
rndomsrmn
7y ago
Mozilla added a feature to allow users to disable DOH network wide (also supported by the notracking list). Info from notracking: https://github.com/notracking/hosts-blocklists#dns-over-http... Info from Mozilla: http
16.
▲
by
rndomsrmn
7y ago
You can also redirect those public dns servers on you router to your local Dnsmasq server with iptables.
17.
▲
by
rndomsrmn
7y ago
Pihole does not make use of dnsmasq's build in option to block entire domains (address=/ads.com/::). This list is also optimized because hostnames that match a domain filter are not included, reducing the size a lot.
18.
▲
Remove almost all online garbage using Dnsmasq
(github.com)
111 points
by
rndomsrmn
7y ago
|
59 comments
19.
▲
by
rndomsrmn
8y ago
Or setup your own very lightweight filtering and caching DNS at home using Dnsmasq and https://github.com/notracking/hosts-blocklists/
20.
▲
by
rndomsrmn
8y ago
Or https://github.com/notracking/hosts-blocklists that uses a dnsmasq feature to block full domains.
21.
▲
by
rndomsrmn
9y ago
Or you just use a very basic dnsmasq installation and make use of a list like: https://github.com/notracking/hosts-blocklists that allows you to also block full domains. Been using this list for several months now with