Privoxy, a non-caching web proxy with filtering capabilities
privoxy.org
privoxy.org
I do use Pihole, but I think this is more versatile. At least it would be if mobile devices were more open... grrmble.
Mitmproxy is great and we use it a lot, but it will have a pretty big hit on your performance. They have a more streamlined tool, mitmdump that is more aimed for these use cases, but it is still not written for performance first.
https://www.cyberciti.biz/tips/linux-setup-transparent-proxy... https://wiki.squid-cache.org/Features/DynamicSslCert https://wiki.squid-cache.org/Features/SslPeekAndSplice
That link is an exact recipe for what I am talking about. It isn't really trivial to setup, but it does work well. Then, you can transparently privoxy ALL of your connections. You have to mix and grind several ingredients together.
Specifying proxy is always easier/better, but transparent with upstream (from squid) proxies is possible. Squid can also do much of the ad blocking as well like privoxy, just without as nice of a config look and feel.
edit: Just keeping things simple, I use squid with dynamic ssl certs, non transparently and have most of the rules I used in Privoxy working fine on Squid as the "one proxy" to run browser through. This prevents needing to monkey with proxy rules. As a bonus idea I also run this Squid on a perma-privacy-VPNd box, and always force certain site traffic through using a browser configuration like ProxySwitch Sharp. If you are really paranoid you can keep your sensitive traffic through your home / more trusted connection (whitelist style) and then route everything else through Squid/Privoxy.
Setting up a nice little Linux VM that simply can't route traffic without the VPN connection is very nice, it ensures traffic thru your little VM can't leak if something on the VPN fails.
Do you have:
A: client -> squid -> privoxy -> internet
or
B: client -> privoxy -> squid -> internet
And some more details on the exact squid & privoxy setup would be nice too.
I've long wanted to get privoxy working over HTTPS, and would love to know the details of how this is done.
You should then have the perfect proxy centipede. For bonus fun use dnsmasq and blacklist domains via DNS too.
Things get much more complex if you want to do things transparently. Now you have to monkey with iptables. The idea is similar though. Start with Privoxy getting all HTTP traffic on a router. Forward to Squid. Have Squids dynamic SSL cert on your client devices.
There was a site with stock quotes that I have been refreshing hundreds times a day so I set privoxy to strip all unnecessary crap like ads, javascript, some gifs etc. and then compress. From 2MB of original HTML page size I went down to 15kB. Times hundred times a day - it had saved me a lot of mobile data.
This is a proxy that works as a "man in the middle"
So, for example, it could block ads served from the same domain as the content or even in the content by using a regular expression that matches the <div> with the ad in it. Like the ads embedded in a google search result.
If interested in reading about the aversion to web ads and concern over privacy in the 1990's and early 2000's, check out IJB's old website. It is loaded with information. The IJB code is still around in at least a few places. While I prefer local DNS and local SSL-enabled proxies to filter ads, believe it or not ijb, as old as it is, still compiles and runs.
To quickly get the list of urls from archive.org, something like:
curl -o ijb.urls https://web.archive.org/cdx/search/cdx?url=www.junkbuster.org\&fl=timestamp,original
exec sed '
/^[12][0-9]* h/!d;
/^[12][0-9]* h/{
s/^/http:\/\/web.archive.org\/web\//;
s/ /\//;
#^M is "\r"
s/^M//g;
}' ijb.urlsI wouldn't recommend running this, as it most likely is an excellent way to get a remote exploit on your machine.