Optimal DNS Ad Blocker
optimal.com
optimal.com
Or you can combine that with https://github.com/jlund/streisand to have a VPN service that happens to adblock (great for mobile).
That said... I like that Optimal have made this too, because neither of the above can work for all devices in a household and more things in the house are tracking you and serving adverts (TV!).
The real questions I have are:
Who sources the list of domain names in there that they will null route?
How will this work with DNSSEC protected sources or whether they anticipate this at all?
How will they become aware of new domains being used by smart devices that are not shared by web sites (and therefore no-one notices and adds it to any blacklist)?
Screenshot: https://i.imgur.com/ELL9CDu.png
Vagrantfile: https://github.com/benlowry/pihole-extended-hosts
My only wish is that it would serve a page notifying me "this is possibly an ad, but would you like to continue?" versus just flat out blocking. I know there's a whitelisting functionality but it'd be cool if I could handle this directly in my actions in the browser.
Will you switch over to a paid service once you're out of beta?
Also what's your policy on logging?
Below (a probably outdated list of) privacy enhanced servers that don't log.
# Swiss Privacy Foundation http://www.privacyfoundation.ch/de/service/server.html
77.109.138.45
77.109.139.29
# www.censurfridns.dk http://www.censurfridns.dk/
91.239.100.100
89.233.43.71
# CCC http://www.ccc.de/censorship/dns-howto
85.214.20.141
204.152.184.76
194.150.168.168
213.73.91.35
# Comodo Secure DNS https://www.comodo.com/secure-dns/
8.26.56.26
8.20.247.20
# DNS Watch https://dns.watch/index
84.200.69.80
84.200.70.40
# Fool DNS http://www.fooldns.com/fooldns-community/
87.118.111.215
# Free DNS http://freedns.zone/
37.235.1.174
37.235.1.177
take the above list to find the one fastest for you: for i in `cat dns.txt|grep -v '^#'`
do
qt=`dig @$i techcrunch.com| grep "Query time:" |cut -f2 -d ':'`
echo "$i: $qt"
doneask them to add you to:
Isn't the best approach is to just buy only devices that either known to not have adware onboard (e.g. "dumb" TVs), or that can be re-flashed with software you can relatively trust?
That only applies to the core OS and its capabilities. The apps can contain all the nonsense they want, because OS can deny the access or feeds the sanitized data if the app's badly written or insists on the business model where user pays with their privacy.
I use this with DD-WRT to get network-wide filtering. It's not perfect (only updates on router boot), but good enough for me.
Additional DNSMasq options:
addn-hosts=/tmp/ad-hosts
no-resolv
strict-order
server=8.8.8.8
server=8.8.4.4
Startup script: wget -qO /tmp/ad-hosts-v4 https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
H_MERGE=/tmp/ad-hosts
H_ORIG=/tmp/ad-hosts-v4
sort $H_ORIG | uniq | grep "^0" >> $H_MERGE
sort $H_ORIG | uniq | grep "^0" | sed "s/0\.0\.0\.0/::/g" >> $H_MERGE
stopservice dnsmasq && startservice dnsmasqI run dnsmasq on a pi as my ISP router is pretty limited. You can't even change the DNS servers, so the pi has to do DHCP too.
I use it to block other things like fixed banner overlays. With caching you can get it to work when you go off WiFi too [0].
Not sure I'd use Google's DNS servers though. Your ISP's are probably better for both speed and privacy. You can test the speed with an old Google project called namebench [1].
Unfortunately my ISP's (Sky, UK) DNS servers aren't particularly reliable. My devices are behind the DD-WRT router that forces its own DNS settings (other servers are intercepted), but the rest of the family connects directly to the ISP router[1]. Multiple times I've been browsing the Internet without issue, but other people have been unable to use the Internet. Changing their device to use Google's DNS server resolved the issue.
[1] Been meaning to merge the two for a while, but haven't got around to it yet
#!/bin/bash
wget -qO- https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts \
| sort -u \
| awk '/^0/ {print;print ":: " $2}' \
> /tmp/ad-hosts
service dnsmasq reload
I know cycles are cheap but that doesn't mean we should be spaffing them up the wall when we can do things cheaper. This avoids double-processing the downloaded content.dnsmasq config as above.
Not sure which one is worse ..?
But if I had not:
- My ISP whose DNS I used, is subject to strong regulations and laws here
- "Additional" 3rd parties are more out of control from this perspective, therefore a significant higher risk, imho
I agree, when you used google DNS before, it's same same...
WHAT WE COLLECT
We get information about you in a range of ways.
snip
DNS service. If you utilize our DNS-based service, we may receive information about your IP address and URLs requested by that address. DNS requests utilize the UDP protocol which means we do not typically get information on the full URL you are attempting to visit (We receive far less information than a company providing a VPN service to you, for example, and that is one of the reasons we prefer this approach as it gives us far less information about user browsing). We do, however, have an IP address associated with each request and so could produce a list of sites visited by each IP address using our DNS servers. We do not know who you are when you use our DNS service, however. IP addresses may also be shared between users, and are not universally regarded as personally identifiable. We only use the IP addresses as follows: (a) the count of unique IPs we use as a benchmark for the adoption of our DNS service, and (b) we may check IP addresses against a free database of countries or cities provided by MaxMind and hosted on our servers, to limit the ability for users outside of certain areas to use our DNS service. We will not use the IP addresses we gather for any other purpose, and we will not correlate or combine them with any other personal information provided by you or other DNS service users, and we will never sell or share any of this information with any outside companies in any way. We may use aggregate request counts to help compensate publishers based on overall site traffic, across all users of our DNS service.
- We may share personal information with your consent. For example, you may let us share personal information with others for their own marketing uses. Those uses will be subject to their privacy policies.
- We may share personal information when we do a business deal, or negotiate a business deal, involving the sale or transfer of all or a part of our business or assets. These deals can include any merger, financing, acquisition, or bankruptcy transaction or proceeding.
- We may share personal information for legal, protection, and safety purposes.
- We may share information to comply with laws.
- We may share information to respond to lawful requests and legal processes.
- We may share information to protect the rights and property of Optimal.com Corp., our agents, customers, and others. This includes enforcing our agreements, policies, and terms of use.
- We may share information in an emergency. This includes protecting the safety of our employees and agents, our customers, or any person.
- We may share information with those who need it to do work for us.
- We may also share aggregated non-personal data with others for their own uses.
Essentially, there are so many reasons for us to share your personal information that we can't help it.Amusingly, the website:
- Uses Google Analytics
- Runs over HTTP (not HTTPS)
If you search jgc@optimal.com you'll find ancient messages from me still lurking on the web. I wonder if that email still receives spam?
I actually went on an adventure of re-registering old company addresses a few years ago.
I am using a local DNS server that does this called Pihole [1] supplemented with additional blocklists [2] for malware and privacy.
One thing I don't see is any statistics ... you might be surprised at how much software in your home is endlessly communicating with companies you might not even have heard of, and that's been a great benefit of taking control of my DNS resolution [3].
[2] https://github.com/benlowry/pihole-extended-hosts
[3] 5.1% of my networks' requests today got blocked - https://i.imgur.com/ELL9CDu.png
How does that help mobile users outside their home network without also setting up a VPN back in?
- reports on who my device(s) are contacting
- no technical capability for anyone else to access those reports
- import block lists from browser extensions / hosts lists etc
- set my own forwarders
- browser extensions so I can see what's blocked, unblock stuff, pause blocking etc, maybe an app on my phone could provide the same functionality
Mostly this is about extending your umbrella to cover privacy/malware, I don't really differentiate anymore between the different flavors of crap websites embed to make the internet more annoying and less safe.
It turns out to be a pretty bad experience. There are tons and tons of legit domains that serve normal content that also serve ads. I used a subset of urls from a popular ad blocking list (https://github.com/geuis/lead-dns/blob/master/lists/easypriv...).
After only a few hours, using the web normally was near impossible. Just a very broken experience. Sadly, since you can't pass a path to a dns server, there's no finer-grained way to allow certain requests to a domain to go through and block others.
I agree, however, that anytime a site is broken that I'm left wondering if I'm responsible because I've inadvertently blocked a CDN or something important.
i put this hosts file on every device/router that i touch.
It works fully local. So infinitely (and this is not even a hyperbole) faster and you won't have to exchange one privacy hole for another on the "cloud".
Not if your HOSTS file is >135KB (the one you've provided is 373KB), you're using Windows 8 or earlier and you haven't disabled the DNS Client service.
http://winhelp2002.mvps.org/hostswin8.htm (about half way down)
I've never had an issue on XP or 7 and I've used the same host file shared above with many, many more that I've personally added (my hosts file is nearly 500KB)
FWIW I do the same, also use that host file at the border router and yes the difference is quite big. I'm always shocked about the extra adverts I see when using a computer or tablet outside of my own network.
My VPN provider (Torguard) provides one of these as well. I'm a little more willing to trust them not to do anything malicious with my DNS requests, if only because I'm paying them.
The bottom line is, if your information is valuable, then it will be in the advantage of those who possess it to exploit it whether you pay them or not. The only real non-moralistic consideration is whether you will stop paying if they start selling.
Either way, "I have a moral obligation to not sell your info, even if you don't pay me not to" sounds a lot better to me than "I don't sell your info because you think you're paying me not to." It's a horse apiece if you're dealing with strangers and you have to take them at their word.
Thinking about companies I've seen the inside of, when the company is doing ok, it's rare for people to just up and do something sleazy. But if they company could collapse, suddenly the moral calculus shifts. Even if they don't do something dubious, they often will consider revenue sources they would have ignored before. As they say, desperate times call for desperate measures.
So I'm much more likely to trust a company I'm paying a fair rate for what they're doing. That's not to say that those people don't turn bad sometimes, but it happens a lot less.
This may have unintended (both good or bad) affects on normal app experience since it's configured on the network.
An "ethical" ad blocking service launched Thursday that allows users to pay their favorite publishers not to show them ads. [...] With Optimal.com, users will pay a flat monthly fee (Leathern told Business Insider the exact amount hasn't been released, but it's likely to be a high single-digit number) to experience an ad free web.
Source: http://uk.businessinsider.com/optimal-launches-subscription-...
Is that even legal?
All ad-blocking is ethical. It's the advertisers job to make me aware of products in a way that doesn't anger me, and they're doing a really shitty job.
They don't have the right to decide how users computers should behave when rendering pages.
https://github.com/apankrat/dnswhisperer
I've been using it routinely for past couple of months and it works really well. It blocks web ads, but it's blocks in-app ads and tracking as well. Tailing a log when launching an iPad game make for an interesting read. If anything slips through, just check the log, add the offender to the blacklist and restart the daemon.
curl -q \
https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts \
2>/dev/null | sudo tee -a - /etc/hostsProtip: Doing this at the DNS and not the browser level leads to lots of brokenness. (Like when you try to sign into an app on your Roku/FireTV and it hangs on a Google Analytics event).
As for the "breaking" some websites, it depends on what you block. Speaking for myself, if blocking doubleclick.net makes one out of thousands hang, then that is acceptable. In fact it's desired because I want to know about such sites. What kind of website would do that? Doubleclick offers zero value to the user. I like this aspect of DNS blocking.
Also it's easy to "whitelist" or "blacklist" certain subdomains if that's what you need to do. Simply a matter of editing a text file, and this can be automated.
As for the comments about what effect this would have if practiced by the masses, I think it would bring these ad-supported search engines and social media sites to a day of reckoning.
Users would have all the power. At least one search engine claims it's focused on users. This would put that statement to the test. Users in control. As it should be.
I am going to try this out, but here I would have even less control since I can't edit the zone file.
Edit: Just turned it on and cleared all relevant caches. Still seeing ads all over Google, CNN, BBC, Imgur and a few others. Don't think this works terribly well.
Edit 2: oh but now the Comedy Central app on my phone won't launch. Turning this off.
https://github.com/jodrell/unbound-block-hosts
It's not terribly sophisticated, but every few weeks or whatever I just run this again:
$ ./unbound-block-hosts --file=/opt/brew/etc/unbound/local-blocking-data.conf
$ killall -HUP unbound