Show HN: MadBlocker — iOS 8 Ad and Tracking Script Blocker
itunes.apple.com
itunes.apple.com
I created this as a proof-of-concept to show that we don't have to wait for iOS 9 to block ads on iOS. MadBlocker uses a hack of the VPN subsystem to block ads, by redirecting requests for ad domains to a bogus local DNS address. Unlike some of the current iOS ad blockers, it doesn't use an external proxy, so no data leaves the device. I also included block lists for tracking scripts, since they're a problem too. Since it works at the OS level, and not via Safari it also blocks ads in (most) apps. It should continue to work fine in iOS 9 as well!
I have some promo codes I can give out too if you'd like to give it a try. If you want one, please just email me at the address listed in my HN profile.
If it's a "hack", won't the possibility be blocked by Apple eventually?
Also, you say on the App Store page that using a big list can slow down browsing, as (I'm paraphrasing) the app has to scan each page against the list; why is that the case? Shouldn't request be redirected the moment they are made, and not before?
Great idea in any case! Will probably try it, as many sites are already almost unusable because of ads (and when using Chrome on iOS the problem gets worse; Safari must block more by default).
To answer your request in more detail: it makes use of a feature that has been around since iOS 7: VPN On Demand[1]. The idea behind VPN On Demand is that requests can be routed to different VPNs (or accessed normally) based on the hostname of a request. This is useful if you get an email from work that has an intranet-only accessible website. Clicking on the link could load a connection to the company VPN for only that work domain without also sending all of your personal traffic through the company VPN. In the case of MadBlocker, I just direct requests for ad hostnames to a bogus local IP, and the ads never load.
That said, while it works in Safari and in most apps, it may not work in apps that implement their own networking or DNS retrieval, which Chrome seems to do.
> Shouldn't request be redirected the moment they are made, and not before?
Yeah, that is what happens, but since every request is checked against the list (since we don't know a priori which request is for an ad), it can take noticeable time on sites that include assets from many external domains (if using the "mega" list or depressingly-long privacy protection list).
e.g. videos showing popular pages loading quicker, load times measured and compared, CPU etc.
Like this one: https://github.com/chrisaljoudi/uBlock/blob/master/README.md...
(blocking is important, but it doesn't worth it if it makes things slower for example)
Here's a demo video of MadBlocker in action:
You might also try searching for it by name on the Dutch App Store.
But does it not mean that you could basically spoof any secure connection (provided you could establish a man-in-the-middle)?
Just wondering, since the VPN destination is not easily verifiable: What stops you from shipping a profile tomorrow that directs traffic towards your server for online banking sites and breaking the TLS encryption using that root certificate?
We're not just talking the big boys here, a bunch of indie content producers publish online and I don't begrudge them a few ad dollars for producing content that's worth reading, or is it that we're making the call that content should be free or is inherently value-less?
I'm not sure of how things will look in the future, but it will probably be a more heterogeneous mix of funding sources. We'll see more subscription-based sites, we'll see more sites run as cashflow-negative hobby projects, and we'll still see ads. We will also certainly see another category: sites the sell your info for money. We'll see sites that combine all of these. I suspect we'll also see more content distributed solely in app form, with in-app purchases buying more content. Since operational costs have fallen and continue to fall, the world won't look so different for a while. I think the best model for consumers is one where ads are the default, and a cheap subscription can be paid to remove them. Microtransactions are an alluring solution, but no one has really made them work yet. There is also a growing trend of sponsoring content before it is created, via sites like Patreon.
In the case of the latter, a whitelist is planned (mostly to correct for false positives). In the case of the former, it's not possible technically since I'm not proxying anything, and the whitelist acts on the request domains ads are coming from not the domains in which they are embedded.
Enabled ad blocking - went to mashable.com got ads as per https://www.dropbox.com/s/gqnf2mebzi74151/photo%20aug%2015%2... turned on mega list, refreshed, same thing.
I haven't tested it yet in iOS9 yet because the VPN system doesn't work in the simulator, and I haven't installed the beta on my personal phone yet since I value stability. Once iOS 9 is out to the public I'll do some testing and make any updates necessary.
* I'm completely fine with this being the case. Before installing I was completely unsure if it would work for iOS9 before trying (not expectant with it still being beta, but simply curious as it's an interesting approach).
It looks like their VPN profile is not included with the app though, and is instead sourced from their website[1]. That means that a) Apple has not inspected the block list (they specifically asked me via the resolution center to list which domains were blocked), b) that the VPN profile is subject to interception or changes of control since it is sourced from a website, c) that updates to the block list require a new download of the block list from their website, d) that an uninstall of their blocklist requires the installation of a new (presumably blank?) blocklist, and e) when you uninstall their app, the VPN profile remains on the device (it is removed upon uninstall of MadBlocker).
1. http://kids.disconnect.me/profile?block_ids=0,1,2,3,4,5,6,7,...
Well worth the price.
To everyone wanting to check validity it should be pretty easy to verify the network traffic.
Will definitely hit you up for a promo code. Cheers.
I suspect you'll get rejected later this year when iOS 9 is released for duplicating a system feature.
There are also plenty of apps that duplicate system features.
Keep in mind that Apple have their own ads network as well, another reason why I'm surprised they'd allow this in the first place.
In addition, the dev said he was using the VPN as a workaround for this, Apple can very well reject this for a different reason.
I wonder why proxies would be wi-fi only. Do you know?