Mmm, Pi-hole
troyhunt.com
troyhunt.com
I see absolutely no negative effects browsing like this. Everything I've come across still works fine. Even sites that detect uBlock Origin and tell me to disable it, will work with that disabled and Pi-hole still blocking the ads instead.
I heavily believe we should be supporting creators, and go out of my way to support them in direct ways (Patreon, buying merch, direct donations, Twitch subs, etc), but I absolutely will not submit my family/kids to the mess that is online advertising these days.
Ads that look like legitimate download buttons, or that run scripts to do cryptomining popunders, autoplay video ads with sound, etc etc. Modern online advertising companies are malicious entities that actively harm users, and I absolutely classify them as malware.
Agreed. Do you disable your pi-hole on sites like Reddit? They vet their ads so not have any of the malicious attributes that you described. All the larger newspagers like WaPo and NYT are also good about this too.
I'm all for blocking intrusive or malicious ads. But quality content depends on ad revenue. The author dedicated an entire paragraph on donating to the pi-hole project, but no mention of supporting quality content with subscriptions or unblocking acceptable ads.
I've still got ads blocked on reddit because they're so clickbaity as of late. They look like posts from subreddits I'm subscribed to and turn out to be an ad, no thank you.
The ads are not malicious, granted, but in the case of NYT at least they're still "blinky". They get blocked at the Pi-hole now. I do subscribe, however. I'd like to turn the ads back on because I view the NYT to be a quality publication, but I'm not going to have something moving out of the corner of my eye while I try to read the paper.
I stick to a search engine rather than browsing Reddit directly. If what I'm looking for comes up in a relevant Reddit thread, huzzah.
I get the contemporary meme is "Agree with great-great-grandpas economics of 'survival of the fittest'." But I feel little obligation to pander to it everywhere it exists.
Maybe I'm an odd bird, having grown up in the remote wilderness in the 80s, no TV, growing food and hunting/fishing, and only using money for things like clothing and basic services (water/electricity/phone).
Of course not. So why would I disable my security software just because a site I visit hasn't been hacked yet? That's just basic security hygiene.
It's the same as with Troy's argument about good browser extensions. Yes they are good today but them being bought for 5 figures and the personal data harvested does not make the news and the users are clueless about it. I rather just not take the risk.
As do I. There's two significant issues I have supporting most sites:
1. They provide only a subscription that is comparable cost to an old-media full subscription. Like most people in the Internet age I have a small number of main sources that I visit daily, and a much larger secondary tier where I may average one or two stories a week. Or they're the sites linked from here that I only visit when something interesting is waved under my nose.
There's no low user or micro transaction options for these, so I get a choice of pay say £10 a month or nothing, for a site I might be getting £1 or 10p a month "value" from.
2. I'm yet to find a site that takes my subscription and turns off ads and invasive tracking. Just ads. Still not an equitable deal.
Leaves things a bit stuck, and me paying out a smaller amount than I'm willing to.
Ars technica. (Subscriptions are tiered but I think this is included in a low tier.)
There is yet to be a quick and simple micro-transaction infrastructure for the web. Transaction costs inhibit micro-transactions. They don’t scale down.
Some are trying to use crypto to do micro-transactions, but even crypto has transaction costs that inhibit how small micro-transactions can be, not to mention the exchange rate volatility.
It’s a big unsolved problem. Gotta spend money to spend money.
A simple, centralized service could easily fill this role with batched transactions. Each reader pays once a month, each publisher gets payed once a month, and those payments can be shuffled about a database trivially. O(n) vs. O(n^2)
Patreon kind of did/does this. There was a big stink not long ago where this appeared to fall apart. The issue Patreon faced was that it was not so trivial to bundle transactions like this. Some creators wanted to get paid in a piecemeal fashion for each video uploaded, etc. For patreon supporters, they would each be on their own separate billing cycle because they decided it would be bad UX to have the first month be pro-rated or whatever.
As much as Patreon is best situated to provide a service like this, I'm not encouraged that they'll do so.
For the sites, sure, everything can be automated. But even in the best case of good browser ui/ux support the burden shifted to users would be massive.
The cognitive cost of trying to decide whether to spend 10c on an article I haven’t read yet costs me way more than 10c. Man that article sucked. Did I just get ripped off by clickbait again?
This argument is what convinced me that straight per-article “microtransactions” will never take off for very low value things on the web.
EDIT: found it: http://hackingdistributed.com/2014/12/31/costs-of-micropayme... - Think it was Nick Szabo.
What’s scary to me is that the one “successful-ish” application we have for microtransactions is mobile gaming. Imagine a huge ecosystem of different beans, gems, flooz, widgets or whatever, and all the dark ux patterns to get people to spend them, and also to hide how much they are spending from people.
The original argument was essentially that there was a minimum transaction size that was cognitively viable at scale.
And any automated system to tell clickbait from quality journalism will incentivise people to trick it.
So at the very least, you need a refund button.
No claps, no money.
Clap as long as you want.
At the end of each month your $10 is divided up by the number of claps you gave.
And if this isn’t for you, then go with ads or be paywalled.
Honestly it almost seems to be worth trying, the potential upshot is _huge_.
Seems to work for them, though I don't know their revenue/profit numbers.
It is true that the cost can vary greatly (which sucks, please tell me of a crypto coin that is 1:1 with dollars), but you can adjust the price in real time and since you are selling a digital product even in an extreme situation you are not going to lose money (remember the transaction fee is pretty much going to be 1-2 sat always).
I refuse to pay a single cent for anything that is even remotely accessible on the Internet and does not result in a physical tangible good being delivered to me, of which I pay $15/mo as acceptable rate-limited mobile LTE bandwidth -- my only communication related recurring cost.
There are several reasons at play here:
- Content quality is not correlated with amount an author is "compensated". In fact quality is almost universally _inversely_ correlated with profitability. Once dollars are attached, out of the woodwork comes a bunch of charlatans peddling useless shit that will not only give you no useful advantage in seeking external information but will actively degrade your life either through dubious advice that will trash your health, finances, legal status, cognitive & mental state, relationships, you name it, or through malevolent action such as selling your privacy or methodical persuasion in you undertaking self-defeating behaviors by hijacking basic human emotional reactions.
- Time has shown repeatedly that volunteers are the entire backbone of quality information sources. I come to HN to have some chance of experts congregating for an actual discussion on certain topics. QA forums, encyclopedias, topic-specific discussion forums, educational materials, news aggregation, scientific research, _all_ is higher quality in volunteer communities before it's essentially leeched for profit by journals, website owners, policy spinmasters, malvertising business, and venture capital.
- "Writing professionally" is not a useful skill in itself, no matter the fantasy colleges want to dream up by funneling the otherwise academically unfit into a program that will lead to a degree thus allowing them to join in on the unnecessary inflationary credentialization of _remedial_ skills. Linguistic mastery is a necessary but not sufficient requirement for creating useful information, you first need a deep understanding of the material you wish to cover. I'd much rather read barely comprehensible jargon from a deranged genius than an eloquent soliloquy by some shill with no idea of what he's talking about other than a general idea that permuting a dictionary in the right magical incantation will summon a paycheck at the end of the week. If you have skills that allowed you to amass wisdom in a field to the point that it would benefit someone else, there are _much_ more efficient and useful means to acquire income and instead use "writing" as a tool for social meaning and development either through reciprocity, self-selection, altruism, whatever.
- The greatest costs are borne not in writing but in deciphering meaning. The combined readership burden of filtering out the wheat from the chaff will _always_ exceed the cost of an author even doing "important" research. This is the crucial point of it all, with some smart people realizing that if information has any value besides propaganda it's due to careful curation, summarizing, and tailoring to an individual's goals and instantaneous state-of-mind, while even smarter people realizing that this will _never_ scale as a business model. Even "clever" workarounds to this problem by infiltrating an individual's web-of-trust in recommendations always end up backfiring. After decades of this scheme being retried and rehashed, I now am completely confident in ignoring whatever bullshit du jour comes out of the mouths of family and friends, and am even running up against the problem of being contrarian against my own internal thoughts.
- Even if against all the odds that you paid someone to get valuable information in the long run you'll regret it. Give an inch, they take a mile. Everyone who is dependent on a paycheck dreams of eventually retiring, and quickly to boot once the actuaries remind them of the future. Once you paid someone for content, you just anchored the negotiations of tomorrow and crystallized the form of how protection money must be paid. "Oh I know you paid back then, but life isn't getting any cheaper and I'd like to get to the beach someday without working so I'm really sorry but I _need_ to add some 'features' that will juice my revenue!" Negotiating with terrorists is not a strategy to get to a stable equilibrium in an iterated game -- the cat has been let out of the bag and it's never going back in. Wake up.
It’s economics. It’s requires modeling, strategies, and thinking equally about all parties because it doesn’t matter whether you like them or not it matters what the future would look like a few years out.
This is not personal I have no ties to ad revenue or professional writing. It’s about putting emotion and philosophy in one basket and solutions in another. You’re allowed to have both, but the latter should be dispassionate.
Just one example on the facts, writing professionally is provably a useful skill. Take even what you may consider a mundane job of writing instruction manuals. if it weren’t useful there wouldn’t be jobs and people being paid money to do it. There’s all kinds of writing jobs that require little independent domain expertise. That’s before we even discuss original or creative content.
You say that like it's a bad thing. Once you've stretched the limits of acceptability beyond the capacity of short-term memory, anything of a 'compromise' is just a token dilution that keeps the same status quo intact in everything except a temporary face-saving apology.
A realistic solution must consider the actions of all parties involved, but it doesn't have to actually appease any of those parties with anything they may want.
It's currently an adtech bubble, foaming to the brim. People speculating in attention-based revenue and side-dealing surveillance armaments through malware distribution to ferment the process should feel the losses when the deal goes bad to set an example that hurting others isn't going to get you a bailout. I don't care about your moral plea for "equality" where we make sure no one suffers the consequences of damaging the commons such as the intrinsic value of information and content.
Because of the adtech bubble, we have a _huge_ problem of noise pollution. Valuable public research cannot be funded effectively because the public realizes the history of paid "results" to turn a profit for media proselytizing and reframing unpopular governmental policies.
Public institutions are no longer credible due to the obvious connections between surveillance, profit, and legislation that is effectively mediated through media companies.
There's a real solution here: puncture the bubble by drying up the money stream. It'll help the useful creators in the long term that are being suppressed by the influx of dumb content and blackholing clickbait algorithms designed to minimize utility to maximize profitability.
Now, for writing professionally being a useful skill. That paragraph was obviously in the context of becoming something like a journalist, blogger, or news pundit where your income is paid by this scam of exchanging between attention and currency though a network of super shady intermediaries.
If you're writing instruction manuals for a living, you're not getting paid for how long eyeballs are on your work so that someone can monetize a reader's susceptibility to suggestion. In fact if I hired you, you'd be paid by how _quickly_ a human can view your instructions and move on with their life in doing something productive.
And that's exactly my point: I know many communications major graduates and many engineering major graduates. The former usually went into the program as a last resort for underwhelming academic performance and trying to latch on to the hype before it bursts rather than being gifted in communication ability. The latter could definitely transition to professional writing, not because of language skills that are essentially expected anyways but because their deep understanding in a subject allows them to distill useful insights that are rather hard to crack otherwise.
For example, I love IKEA/Lego instruction manuals not because a random "professional writer" with no independent domain expertise was able to checkmark that off his daily tasklist, but because the manual was made by people with incredibly sophisticated knowledge of how to visualize and communicate the ideas of physical assembly and knew their audience appreciates that expertise. If you're able to document the assembly process, you're qualified to critique and help improve the usability, design, and even materials engineering that ultimately influences what you write in the manual.
This reinforces the idea that if you're just a writer, you're useless because you _should_ be funneling what insight you distilled back to the process your're documenting. And then you're not really a writer, but an engineer.
And just because there are jobs and people being paid money to do it doesn't mean it's useful at all. Biggest fallacy I've ever heard.
I guess I'm saying that I couldn't disagree with you more; if all the content I didn't pay for went away, I doubt I'd be negativity effected at all.
My take is that no matter what people say they prefer to subsidize their content by viewing ads over actually paying the equitable price for it.
The problems are:
- Your definition of 'equitable price' when we live in a time where no single human can digest across their lifetime even a single year's worth of the glut created.
- The quality is universally garbage and as an information consumer you'd still have to spend your resources in thinking critically whether to accept and update your assessment of the information. If you're consuming 'content' as escapism well then you still might consider a more cost-effective route such as heroin or even direct neural stimulation.
- Consumers rightfully work out the long game plan of content creators. They'd like to not view ads but know that once you've climbed above the threshold of starving artist you'll get greedy and the ads will come right back. Always. No exception.
The market shows that advertisers are outbidding consumers who don’t want ads. That sets the equitable price, not the desire of the consumer.
I don't have a problem with tv ads for shampoo that I won't ever buy. I do have a problem with a web page that surrounds a legit news article with bizarre ads with cockimamy health claims, and links that don't go where they claim to go.
If a website says, "Pay up or look at these 'spider veins' ads" that's entitlement, arrogance and open contempt. That's not treating me like a desired customer.
For TV, I'm happy to pay for renting from google or a monthly fee to Netflix. In return I never need to go to the cinema, I watch films at the time that works for me, and no ads!
Yeah, I'd be happy to pay for quality video, podcast, and articles, but not 5$ to each site I want to read from.
[1] "Every document can contain a royalty mechanism at any desired degree of granularity to ensure payment on any portion accessed, including virtual copies ("transclusions") of all or part of the document." https://en.wikipedia.org/wiki/Project_Xanadu
I kind of like tying this into U2F. I think FIDO and the like will rollout as oauth has done - slowly but becoming the "default" way.
If as part of the initial sign up process, you authenticate your public key on site A, as being someone who can have a share of your monthly subscription... then we have built a distributed subscription service ...
i think
I like the idea
This is an interesting problem!
Support your favorite sites with Brave’s blockchain-based tokens called Basic Attention Tokens. (coming soon to mobile)
[0] https://twitter.com/BrendanEich/status/1036724148146384896 [1] https://brave.com/faq-payments/#previous-bitcoin-wallet [2] https://basicattentiontoken.org/
"[Brave] browser blocks ads and website trackers. Currently, the company is developing a feature that allows users to opt in to receiving ads sold by Brave Software in place of the blocked ads. Brave intends to pay content publishers 55% of the replaced ad revenue. Brave Software, ad partners, and browser users would each be allocated 15% of the revenue. Users could donate their revenue share to bloggers and other providers of web content through micropayments. The browser claims to improve online privacy by sharing less data with advertising customers, but will target web ads by analyzing users' anonymized browsing history." -- Wikipedia
I consider this ad-replacement scheme extraordinarily scummy. It sounds like the plan is to use protection racket strategies to get the target publishers to buy in.
Unfortunately I'm unwilling to change browser for this, and would rather see it as an addon or local software install so it works on the user's choice of browser, but it's a very good idea.
As it currently stands, a large chunk of the newspaper industry in the states is willing to block the whole of the EU, when it could offer it that model, so I wouldn't hold your breath.
A source at Tronc says not only have most of the chain's papers blocked EU visitors because of GDPR, but Tronc "currently has no plans to support the EU" because doing so is seen as not economically viable
https://twitter.com/mathewi/status/1001571559679582209?lang=...
A "tip jar" or micropayment model to supplement subscriptions would be a great option. Unfortunately I think processing fees eat up a significant chunk of your take to the point where it's not really profitable to build a business model around it. Even if you get a great solution going, getting buy-in from the number of vendors you'd need on board would be prohibitively difficult. The only ones with the reach would either be inclined to lock it down and stick with the ad centric model (Facebook, Google) or just don't have the organizational culture to give it the attention or support it would deserve (Apple, Amazon).
In the old days you could go to a corner newsstand and pick up a newspaper, even from one of those little boxes on the street. This let you just buy if there was something interesting that you needed to look at that day without committing and, importantly, without handing personal financial information to who-the-hell-even-knows. A payment infrastructure that makes this quick, easy, and cheap enough to where cost isn't a concern would be incredible.
Except it would work a bit differently. Say I approve N number of sites (NY Times, WaPo, EE Times, etc.) They each get paid out of a monthly fund based on how much I visit each of them.
I'm using https://blendle.com, which offers a wide variety of publications with payment per article (usually something around 0.70 EUR, with the odd 1.99 EUR for articles from DER SPIEGEL). They also have a daily mix of manually curated content and content based on the articles I purchased in the past, which works really well. I'm afraid it's only available in the Netherlands and Germany so far.
I didn't know the Brave browser had a payment model built in, will give this a try as well.
btw, I've purchased a few articles from Der Spiegel but they were around 0,75€.
As do I. There's two significant issues I have supporting most sites:
If some big company like Apple, Microsoft, or Amazon wanted to get behind micropayments, they might be able to actually get it started. It would basically amount to disrupting the advertising model itself. Advertising would morph into influencer media produced at the behest of advertisers, but much of media would be much freer from the worst depredations of advertising.
Unfortunately, I think the incentives are too loose. Users aren't obligated in any way to pay for links; as usual, humans aren't charitable enough to actually sustain public goods voluntarily. Secondly, the aggregator site isn't under strong incentives to pass on revenues (which applies equally to ads).
The 'microtransactions problem' using 'aggregation/centralization' you're describing would be readily identified as the newspaper industry a few decades ago. Nowadays you have to wrap it up in a healthy dose of cryptocurrency scamming, federated networking bullshit, and other huckster lingo to make it seem like a radical approach.
Newspaper companies, which allowed patrons to exchange a few cents for a daily source of vital information curated by professionals across a wide array of expertise, distributed money received in patronage towards the journalists, editors, fact-checkers, you name it.
Of course, that isn't the full story. What newspaper companies did was become the mouthpiece of the government and eliminate any useful information, filled nearly all the pages to the brim with huge obnoxious ads with little text remaining, started some perverse incentives with journalist pay forcing the smart ones to abandon ship a long time ago, and helped build a mass culture of frantic zombies who cannot tell the difference between fact and fiction, parroting whatever they read as a sort of social lubricant, and trained to resort to looking on a page for the local weather information yesterday that could be far more accurately sourced now by looking up to see if there are clouds above.
Good riddance to 'content creators.' Don't let the door hit you on the way out, and HN will never receive a cent of my money. :D
This is exactly the response for anyone that is frustrated by blocking ads impacting revenue for web publishers. Had the ad tech not become so invasive and pernicious, users wouldn't be going out of the way for solutions like this. The advertisers have essentially forced our hand.
OH! C'MON!!! I believe in the conference, but I'm not going to share the link with that ad on it.
It's been explained to me that the website owners don't know what ads are being served up. All they know is they signed up for an ad service. If that ad is a redirect to a porn site, the website owner has no clue unless people complain.
And that's why I ordered a raspberry-pi to set up a pi-hole.
I get that a lot of my friends won't like this. They're in advertising and marketing, and they insist that they're one of the good ones. Fine. But the bad ones are REALLY bad.
Also. I've spent HOURS opting out of tracking cookies. Then I heard that my effort is only as good as the entities that respect that I opted out. OH? WOW!
So, when I hear people complain that we're hurting them, and they're one of the good ones, it ignores the real problem. Look ...
if I was bitten by 10 dogs out of 50 dogs, I'm gonna have a problem with dogs. Period. You can insist on how friendly your dog is, but no. Talk to the other dog owners before trying to get me to take another risk.
Exactly my stance on whitelisting advertising. I am sure there is a good amount of fair advertisers out there, but the area at large is full of scum.
I would start with a full-on disable of 3rd party JS but I know that would break a whole lot of other and actually needed functionality. So I have no good solution except not to trust anyone. Pi-Hole is my next stop as well.
Where in THE hell are you going on the Internet? Wait, don't answer that. I only wonder because we sit at around 20-30% at our house (which is still ridiculous). But approaching 90%? Maybe I need to crank the blocklists up a notch, but I can't imagine even surfing porn sites all day that I could get anywhere near that percentage of blocked requests. But, man, I enjoy a challenge...
You can trace offending devices and traffic via pi-hole logs. The UI is a bit clunky but gets the job done.
Container link: https://hub.docker.com/r/pihole/pihole/
Edit: word
https://github.com/openwrt/packages/tree/master/net/adblock/...
The childproof network example is the fitting how-to you can learn from: https://forum.openwrt.org/t/kidsafe-or-guest-wifi-forced-saf...
Despite this, I run pi-hole on an RPi that I have done so much as a reboot on in two years.
edit: link to OpenWRT with a list of supported hardware that is relevant to the parent's question
Was that what you used? Or was it something else?
Take care that the router has a boot mode which allows you to overwrite the firmware via TFTP. That comes in handy in case of trouble with a particular firmware version (e.g., router stuck in a boot loop).
Of course this board doesn't come with the features of a fully-fledged consumer router, such as built-in DSL/DOCSIS modem, DECT, WiFi, etc, so your mileage may vary. It comes with 3 independent Ethernet ports and 3 mPCIe slots though.
[1] http://pcengines.ch/apu2.htm [2] https://openwrt.org/toh/pcengines/apu2
I run openwrt on it and use the "adblock" package which works like pi-hole (minus the nice web stats). Having it be a plain x86 CPU is nice—For example, I compiled Telegraf on my local Linux machine (since openwrt doesn't have a package for it) and was able to just drop it on with minimal problems.
Not cheap, and sometimes unforgiving if you don't know exactly what you are doing, but worth every penny in my opinion.
Ironically, went to Unifi after reading Troy's blogs about it - now regretting it immensely as the hardware is nowhere near as powerful as the Omnia.
The fix is to disable this with "echo 'Uninstall("knot-resolver", { priority = 60 })' >> /etc/updater/conf.d/user.lua" over SSH so it stays disabled. You can do this for any service you modified or disabled, and the documentation barely mentions this (it's a real showstopper bug until you diagnose it - no connectivity whatsoever).
I was looking for an openwrt-compatible router a few weeks ago, this is 2018's consensual cheap & able & easy-to-install router. It's easily the most frequently recommended home router for openwrt these days. And yes, openwrt's Adblock package is awesome.
And to come back to your original question, to do your own research, I recommend you search/ask on https://www.reddit.com/r/openwrt/ and https://forum.openwrt.org/ , it's a question that pops up frequently.
https://pi-hole.net/2018/08/06/pi-hole-v4-0-released-with-ft...
(I.e. https://en.wikipedia.org/wiki/Arc_(programming_language) )
Pi-Hole is a drop in replacement to an existing network setup that doesn't require hacking your router to install a custom firmware. It will also persist router upgrades.
My only gripe with Pi-Hole, which isn't their fault really, is that power losses can quickly corrupt the Raspberry Pi's SD Card. I have my network gear on a battery backup but when I was first validating Pi-Hole I had it sitting on my desktop and managed to corrupt the SD card with power drops.
The best filesystems for robustness against power loss seem to be log-structured filesystems like YAFFS2 or QNX's ETFS. The design of the filesystem basically means that a block is never modified on flash, only obsoleted by future writes. The trade-off is that the filesystem has to be reconstructed from the raw blocks at power-on but it's incredibly robust. And the filesystem also has to be garbage-collected before additional writes can be performed. But as long as you run your filesystem below capacity this isn't a big deal.
(1) Install "1Blocker X" -- not free but it's cheap. (2) It has a huge number of rules and protects your Safari pretty damn good. (3) You can disable the existing rules if you so choose. (4) You can add new ones based on URL regexes or CSS rules.
I am still using it actively both on my iPhone and iPad, one of the best investment in apps I ever did.
It seems to only impact during NIC changes, but I VPN and was moving my computer enough that it was causing me issue.
I'd rather have a separate service to run it.
I'm doubting whether electricity cost might be too high (it's getting mighty warm), but I haven't measured it, yet.
So far, I love my Pi-Hole. Absolutely no problems with it.
I wasn't familiar with these terms and they are a bit ungooglable. :-/
DoH = DNS-over-HTTPS
DoT = DNS-over-TLS
Look at his comments and replies to gauge the audience for his content - deploying more privacy and security tools and knowledge can only be a good thing
I stopped using it as mine was seemingly hacked (100,000 lookups or so in a short time, presumably some sort of page-impression generation?) and I hadn't the time to trace if it was a problem with the project or not.
What makes the Pi-Hole organization any more trustworthy? (and the software stack it all depends on)
Personally, I'm inclined to trust them both and hope that the long arm of the GDPR will be effective. Optimistic, I know.
Huh? DNS is hit even if the site is SSL. Unless the site has HSTS, and you've got to the site before; DNS poisoning is very much doable.
Are you thinking of some downgrade attack vector?
Even assuming the use of HTTPS, there are other threats. For example, PiHole redirecting you to a MiTM, who simply observes your connection and can learn sensitive information from the timing and length of your sessions.
I am not arguing browser extensions have strictly less access, just that both PiHole and your extensions have a fairly catastrophic level of access...
You can also inspect the block lists to ensure they all go to 0.0.0.0 if you’re worried about mitm attacks.
>you could do the same with ublock
that was in response to
>This should just be dnsmasq, for which source code is readily available and inspectable. You can (and should) compile it yourself if you don’t trust someone else’s binary.
Also, odds are a lot of you are running dnsmasq on home routers already without knowing it, and those are worse from several perspectives, including patching (consider CVE-2017-14491), overall appsec vulns (CSRFable RCE: a thing in home routers!), and exploitability of network position (e.g. HTTPS stripping on any non-HSTS website).
I still think you are understating the risk of a malicious DNS server. As you note, many users will have unpatched IOT or network facing devices (e.g. cameras, baby monitors or other smart gadgets). With DNS spoofing they all become vulnerable to a remote attacker...
Maybe we can agree if we consider different types of users? Technically skilled users are likely to stick to secure hardware and have an awareness of their general software vulnerability. They choose their passwords carefully and are concerned about compromise. Less saavy users are more likely to own insecure devices, use the same password everywhere and be less concerned by account compromise.
High skill users have more to fear from a Web Extension, its impact is undetectable and can siphon passwords. Low skill users have more to fear from a malicious DNS server, they won't notice the lack of HTTPS on none-HSTS sites and their hardware will get compromised remotely.
Which one of these is worse:
a) I might be able to convince a bad IOT device to connect to an IP I control which may or may not let me do something interesting,
-- or --
b) I can just use your session cookie for GMail and reset all of your passwords for your IOT services and also everything else? And since I get UXSS, I can scan your internal network and get XSS on that IP/origin too. Or, I dunno: try to use UXSS to log in to your home router and change the DNS server to a machine I control?
The crux of your argument seems to be "it is more valuable to be able to point an IOT device at the wrong IP than it is to get UXSS on a machine on that network". That seems obviously wrong to me for any user, technical or not. If anything, it's worse for non-technical users, because they by-and-large don't have 2FA, making e-mail compromise far worse.
I only use the quality of the software in one sense: to bound how bad DNS resolution could possibly be. dnsmasq has had more than one of those style of game-over vulns. A malicious WebExtension or DNS server is indistinguishable from one with a bad enough vuln.
If PiHole is malicious, there is already an attacker on your network, DNS Spoofing is just one example of the possible consequences. The PiHole can also port scan, connect to services etc. I don't think mounting an effective phishing attack on a user would be very hard.
My point is that both scenarios are catastrophic, and its hard to justify choosing one over the other on the grounds "the developer might be malicious". Telling people "don't worry a DNS server can't do much" is massively understating the problem, considering all the local network devices directly exposed to the PiHole device and the fact it is the DNS server.
As I said, I use both and cross my fingers that Mozilla / Open Source code review / the GDPR mitigates the risk of a bad developer
I have also already argued that an extension does not need to be malicious -- just buggy -- to get UXSS.
In contrast, UXSS provides an attacker on your network that already has access to everything inside your browser. That's banking, email, keylogging credit card numbers, etc. That's the end game right there.
A malicious rPi on your network is quite a few steps away from there, you'd still have to phish and deal with HTTPS/browser security and unlike UXSS that only gets you one set of credentials.
What? The entirety of the project is open source. In fact it's easier to look at the source code that makes up PiHole because it's all in one spot in Github.
Pi Hole is open source, so if someone did try to sneak in some malicious code, it would be seen.
Edit: Heartbleed was a good example of this -
https://www.csoonline.com/article/3223203/vulnerabilities/wh...
> The most ironic thing here is that OpenSSL is open source software. Anyone could look at the code, and presumably hundreds did, but nobody noticed the fairly elementary coding error.
It would take every creator to accept the bribe for the ads to go through. Well, if the extension starts injecting ads it's another story...
Remember the warning signs of craziness with NoScript? It's like you guys never learn!
HN is a community. Users needn't use their real name, but do need to have some consistent identity for others to relate to. Otherwise we may as well have no usernames and no community at all. That would be a different kind of forum. Anonymity is fine, and throwaways for a specific purpose are ok, just not routinely.
https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...
The idea that we have a moral duty to sit passively and absorb “experiences” in their intended form... I just don’t see how that works long term. It will just mean we get abused more and more and we have to take it.
No, if you want my business you have to find a way into my consciousness that is compatible with the way I arrange information around me. That’s always been the deal. You can put a free circular in my mailbox and I am free to toss it without looking.
The whole approach of Pi-hole feels misguided. Blacklisting domains and hosts should be something easily done on my device locally. Then it comes with me when I visit friends or coffee shops, and it's easy to temporarily disable when it breaks something I'm trying to use.
The fact that I can't do this on things like my phone really illustrates how little control we really have over our own computing devices.
I tried to set this up on my own using a VPS and Pi-Hole and it did work for a while. However, bad actors eventually found the server and started using it to perform DNS amplification attacks against, of all things, cricket news websites. I don't know too much about networking, so this may be a limitation of the DNS protocol. However, it seems like Quad9, Cloudflare and the like have figured out a way to prevent this sort of abuse... So, if any provider out there is reading this, please add this capability and I will gladly pay to use your DNS service.
Out of curiosity, do you have any idea how they prevent the scenario I outlined (e.g. metadata, traffic analysis)?
At that price, I doubt they do.
https://adguard.com/en/adguard-dns/overview.html
Note that obviously since you are sharing all your dns requests with them, it's terrible for privacy... :'(
Right. I'm not defending this service in any way, but couldn't you say the same about Quad9 or Cloudflare?
You could set up pi-hole as a recursive dns server: https://docs.pi-hole.net/guides/unbound/ That way you don't have to use a public dns server like Cloudflare. However, since (as far as i know) dns requests are not encrypted, this is not perfect either (security wise).
At least when using Cloudflare you can use DNS-Over-HTTPS: https://docs.pi-hole.net/guides/dns-over-https/
You don't want a malicious app do this in your back so that when you type alice.com, you see bob.com instead.
Fortunately, to some extent, HTTPS or GPG come to the rescue.
I get 126 requests and 2.3 MB transferred on Daily Mail Australia, which seems comparable or better than what Troy saw with Pi-hole. See https://postimg.cc/3WYwZf3b
(Disclosure: I work for Mozilla.)
I wonder how long it's going to take for ads to be implemented server-side entirely.
No doubt the reduction is important, however as per screenshots, the reported reduction should be considered somewhat inaccurate as he forgot to check "Disable cache" for the Pi-Hole version, while it is checked for the non-Pi-Hole version. We can see resources pulled from browser cache in the Pi-Hole version.
With browser extensions it is typically easy to disable the ad blocker one time and check if that fixes it. With pi-hole IIRC, it was much harder to do.
Don't visit those sites!
They want your eyes and/or your money (if a subscription is an option) and you don't want to give it to them. Just stop going there!
Edit: I don’t understand the downvotes. Sites aren’t obligated to give you something for nothing. Why does it feel like that’s the default view here?
I'd love a pi-hole like solution that was as easy to temporarily disable as a browser extension.
Either they’ll move out, resent you, deal with it, or you’ll do what they want?
I wish it would redirect to a different local webpage that allows you to click a button to temporarily unblock the domain for your ip, like the ublock blocked webpage that pops up sometimes:
https://arstechnica.com/civis/viewtopic.php?f=3&t=1424503
If it gets abused, then you can turn it off as an option.
2. It has a DNS option[1]. Set it to your Wireguard server.
3. Setup unbound with a public ad domain list. (No link for this, Google is your friend and there are several different options with minor tradeoffs.)
You're done. Now unless wireguard, a soon to be kernel project, or unbound injects malicious code, you're safe.
Edit: oh and this also works on mobile
[1] wg-quick man page - https://git.zx2c4.com/WireGuard/about/src/tools/man/wg-quick...
It's an extension but given it's less opaque than a generic ad-blocker I feel more in control and that it's less likely to go 'rogue' like adblockers do.
The most frustrating thing about UM (which is the same problem I had with NoScript back in the day) is that some scripts call other scripts. So, particularly when I'm trying to play an embedded video served by another site served through a CDN, the process for getting the damn video to play is something like:
Click video -> Open uMatrix -> whitelist some scripts -> reload -> whitelist more scripts being loaded by the first batch of scripts -> reload -> whitelist some XHR references called by new scripts -> reload -> finally whitelist the actual media being served.
I rarely see an ad. I didn't see Troy's responsible sponsor message either. I should have and would have if he had chosen to display the thing without the need for scripting. So I don't feel hugely guilty.
edit: Okay, it's not blocked by default with uMatrix: https://i.imgur.com/B97lf35.png
vlc is a better video viewing experience (and better on battery) than a browser and you can usually start playing a partially downloaded file
I do not mind, but I can imagine it easily gets annoying for many people rather quickly. (OTOH, those people would not care to set up Pi-hole, either.)
Ublock seems to do an okay job of blocking most ads and tracking stuff so I'll stick to that in the meantime but I would be really interested to see a uMatrix tutorial or something like that.
There is very good youtube tutorial of about 7 minutes that explains it use.
Instead of clicking on the uMatrix icon, you click on three dots and then on uMatrix
Rather than bringing up a small window, with all your settings, it brings up a new tab with your settings.
Other than that it is the same! And it will work when you are away from home without needing a VPN to a Pi-Hole.
I installed a pi-hole in my home network about a week ago, and it survived less than a week.
My wife likes using sites like eBates when she shops online, and it redirects her through a random sequence of tracking sites before landing on a site like the Gap. It caused all sorts of problems for her, as those sites were being blocked.
If I was going to keep the pi-hole running, I would have had to constantly be adding white list entries. Or, I could have manually created a black list from scratch. I was not interested in doing either.
I found that dropping a handful of domains in uMatrix got rid of most ads (but not tracking), and that was good enough for my uses.
That's why Safari's content blocker API is so great[0]. Creators of these extension have no access to my data and it's faster than normal extensions to boot.
I'm using Wipr, which seems to work just as well as pi-hole on the example pages. Blocked his advert too, or at least I can't find it cough.
[0] https://developer.apple.com/library/archive/documentation/Ge...
There's no reason to have an ad blocker be anything other than local. Sure, it should be able to pull more rules, but during operation it should just match those rules. There's no need to have it be written in a language with e.g. XHR or whatnot.
As an additional system-wide layer, I subscribe to Peter Lowe's ad block list with Little Snitch. Now I can block all outbound requests to ad servers system-wide.
As much as I like PiHole, I don't think it's a one-stop solution. It's generally easier to manage stuff locally on my system. I think the big advantage is for software that isn't as open (like iOS, tvOS, etc).
I find that working in layers instead of trying to find a singular solution is easier to work with and provides more flexibility.
With Pi-hole you can disable an adblocker when something doesn't work and still enjoy a fast web.
But Pi-Hole still blocks the majority of ads, so it is possible to use it exclusively if you just want to make the web usable again.
It's also great at home for family members who just want to surf faster and more private and secure but don't mind a couple of ads here and there. Especially when it comes to mobile Apps.
I also want to highlight that most domains that are blocked are usually tracking services which makes Apps and Websites incredibly slow and increase traffic to a large extent. I think blocking those "services" is the true beauty of Pi-Hole. Ad-Tech is only the tip of the iceberg when it comes to commercialised tracking.
But I have to wonder why the ad networks don't require content creators to place some "ad libraries" into the web servers or CMS systems directly, so that the ads are served exactly the same way as the content (same domain, same pages, etc).
That's my nightmare scenario. I figured it would have happened everywhere by now. I see it in a few places but it seems pretty rare.
Is it the heterogeneous server-side environments that are slowing down this approach?
If it ever takes off, what is the mouse to do?
(1) Their current tech still works on most users so it's not economically justified to invest several times more just to catch a few extra percent of the users (the tech-savvy) in their net.
(2) They are not technically savvy enough to figure it out (thank Cthulhu if that's true!).
(3) They do not want to pay for the extra bandwidth costs and to upgrade their servers. And they will have to do both because looking at any ad inspection article reveals that the ad/tracking bandwidth can be easily anywhere from 3x to 20x the bandwidth needed to serve the content itself. Furthermore, the ad/tracking tech uses elaborate scripting techniques to avoid part of the automated defenses of browsers or network devices. Running those scripts 24/7 increases your electricity bill significantly.
Overall I believe it's a case of "we could probably do better but we get a hell of a deal for the minimal investment we made". Which is really good for us the techies -- because they leave us alone -- but seriously sucks for everybody else.
Uh, sorry, but uBlock Origin blocks it. Also, does anyone else finds themselves jumping straight into `reader view`?
In this case, the largest resources are Javascript and CSS (yes 1.2MB CSS files!). The weird thing is that it appears to be making requests with different cache-busting strings and getting resources that are the same size.
(32MB now, I haven't done anything on it since starting this post)
The new gmail is the slowest web app I have ever used. It's gotten so bad I've started managing my email on my relatively snappy inbox iOS client.
It wouldn't be so bad if they didn't load so much crap, like the gchat functionality nobody has used since 2008.
Android P uses 10x as much memory as it did from Gingerbread, I don't feel as if there's 10x as many features.
Turns out, Al Gore doesn't like it, either: https://www.typotheque.com/blog/gores_choice
With remote fonts enabled on https://www.troyhunt.com/mmm-pi-hole/
24 requests 3.12 MB / 3.06 MB transferred
And with remote fonts blocked: 20 requests 2.96 MB / 2.90 MB transferred
It's not just ads you have to worry about.Otherwise, it's a godsend, especially on mobile. Though some...unscrupulous sites...I visit on mobile on some occasions still manage to redirect me to crazy shit. But I get way less adds pretending I have a virus.
I'll continue putting my trust in uBlock Origin on FF for now, until I hear about any malicious PRs that get merged in /shrug/
Also, you can't usually specify DNS servers on cellular connections. The VPN setup would address that.
From what I understand this is only iOS.
I don't think anyone should trust cellular connections at all for many reasons. Especially because my country (Russia) is the only one in Europe which has an office of CEIEC (chinese surveillance gov company) which as of now makes Orwell's tales come true in Xinjang.
My favorite thing about it is ad-blocking in mobile apps. I tried to use it with OpenVPN on my android phone for ad-blocking when I'm on cellular data, but the speed it was unbearable. I'm not sure if it was my crappy router or what, everything I read says that DNS routing should be neglibible to speed.
The downside of pi-hole as opposed to a broswer extension is it's more difficult to allow things when needed, and whitelisting specific URLs can be difficult and slow to take effect.
But this would require having a full-blown PC running 24/7 and increasing your electricity costs by at least a few bucks a month. It would be much wiser to buy a $10 Pi Zero W and put Pi-Hole on it.
Also a reason to use a dedicated NAS appliance. Instead of the 60W minimum idle that desktops have, your at 1-10W idle with rpi zero and NAS appliances.
Small laptops might have a more efficient idle although, so YMMV.
Agree about ad-blocking on mobile. The killer feature with Pi-Hole is that you don't have to set anything up on each individual device; anything connected to your network suddenly has near flawless adblocking.
2) I know my next suggestion goes against net neutrality, but what would stop an ISP from doing something similar at the level of their router (or cluster of routers)?
Update: Actually for 2), some places that provide Internet access to their users who aren't ISP customers (e.g. businesses, malls, municipalities, colleges/universities/schools) could roll this out as well citing bandwidth savings (therefore cost savings).
Sell it as a turn-key appliance in a box with three ports: Network in, router in, and power. Operate as a transparent proxy, automatically update, web interface on the inside port only, etc etc.
Biggest issue is ensuring it's got enough performance on both Ethernet ports to not bog down traffic.
I don't mind an ad or two. I don't want you siphoning my network and computational resources without compensation.
So the ideology of capital, which destroyed community morals, is now having it's own tawdry ethics trashed. It's not news that the news is failing. This Author Wrote 7 Reasons Why You Can't Make 20th Century Business Web-Scale.
You can't separate all the interesting aspects of this distinction and ignore the ones you don't like.
As an example, lets say you borrow my truck. You compensate me for the use of my truck to move some boxes in town.
But then you use my truck to tow a trailer across the country. That is more wear and tear on the vehicle.
And then you take my personal information that is on my vehicle registration with my home address and sell that to an ad company.
Finally you return my truck with all sorts of junk that was collected while the truck was being used.
How about what is done with your personal information?
When you visit a website are you shown which tracking cookies will be left behind?
You cannot stop visiting the site, once you have visited the ads have been loaded, the cookies have been dropped and your info has been mined.
https://github.com/apankrat/dnswhisperer
It's been quietly spinning on our mail server for a couple of years and it works just as you'd expect it to. Block ratio is around 50%, with no notable effects on browsing experience. It also blocks various in-game ads on the iOS devices. I update the blacklist now and then, may be once every 4-5 months if that, but it's largely maintenance-free.
Highlight of the article right here.
I'm conflicted, I'd like for there to be some mechanism where reasonably implemented ad systems can flourish.
Xfinity/Comcast hardware (cable and WiFi integrated) works with the Pi-hole how? I can't change the DNS addresses on Xfinity hardware. Ok so I have to buy my own router, in which case Xfinity blames all problems on running by own hardware.
Another ISP with which I'm familiar, when running my own router and assigning DNS of my choosing (any, DNS Watch, Google, Cloudfare, OpenDNS, whatever), and the ISP actually redirects the DNS requests to their own DNS servers anyway. The only two ways I've found to get around this is: always on VPN, or DoH using Firefox+Cloudfare's test they're running. In this case, it's deceptive having a router that permits me to assign DNS addresses of my choosing.
In either case it means distrusting ISP hardware, getting your own cable modem, or getting your own network router, and also a Pi-hole. It's esoteric knowledge. This is a remarkable industry failure.
Once the pihole has been setup and has an IP it becomes a DNS server, you just then tell your end devices to use the piholes ip address as the dns server.
DNS requests either go where you want (static IP addressing) or where to the xfinity/Comcast (DHCP addressing).
And no, the internet is not safe by default, by neither is the real world.
Even that is blocked by uBlock Origin with default settings. I wonder how it knows it is an ad?
Sometime, it's convenient to be able to switch it off quickly (as someone mentioned, certain sites will mulfunction): so I created a simple Alexa task to turn Pi-hole on and off using voice, leveraging the pi-hole api.
However, I would recommend adding a few more decent block lists to the default ones. Also updating these lists through a cron job on a more frequent basis is a good idea. Here's a script that you can use to setup pi-hole and additional block-lists: https://gist.github.com/user501254/1d4c8cb9f22fb51ae970f5fe0...
Also make sure you are using 1.1.1.1 as your secondary DNS service. So this way in case your Pi-hole running RaspberryPi is down, your devices would be still be able to access the internet with some privacy.
I took the most recent block lists that uBlock Origin was using at the time and filtered out all the css-based selectors to just get the domains and urls.
Unfortunately it basically broke nearly every site that I went to, largely in part to blocking some top-tier domains from Google I think.
You could run lead-dns locally on your machine, or on another machine on your network.
I still think its a good approach and will be looking into Pi-hole since its a lot more developed than my early experiment.
Has this changed recently?
EDIT: Answer: probably not, but that's irrelevant because this Pi-hole appliance apparently just does DNS, not full traffic routing. Makes reasonable performance possible, at the cost of granularity.
To block ads when I'm not at home, I use WireGuard and pass DNS traffic through it.
Monetizing such service sounds tough as you have very minimal leverage over the users (by design!) but perhaps a Patreon/Foundation would be sustainable, similar to how Wikipedia is? Perhaps it could be bundled to a VPN service?
It would be easy to exploit people and as you say it's basically impossible to monetize. There would be motivation to do so.
Don't bother trying to tell me this will be optional. Absolutely nothing will make me trust you after the MR. Robot incident. I would cut off two fingers to use Safari on Linux and Windows.
Already fully invested -- a MacBook Pro, an iPhone X, an iPad Pro. Only thing missing is a desktop machine.
The fellow technical crowd in HN and Reddit loves to crap on Apple for "slowing down progress" but Safari is a very solid browser. Between a good ad blocker and reading mode, it actually gives you control and styles pages for... you know, reading. I really like Safari on all my devices because it allows me to consume content how I want and forces the websites to behave.
That way one could configure only the browser to use this and it would also work on phones that are using LTE (and not adblocking when using home Wi-Fi only) [0].
[0]: https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1...
I don't think anyone has written custom DoH stuff you can easily run yourself yet.
Killing two birds with one stone here: proxying access through a VPS to hide the home IP address && blocking ads.
Apart from it occasionally blocking legitimate sites that begin with the word "ad" (something like, say, "adrian.blog.thing"), it works great. Because it's an HTTP proxy, it offers an interface for bypassing these unintended blocks.
I personally hate wondering why something's not working and having to go through every extension to debug my browsing session.
Consider supporting them (but not too much ;): https://www.patreon.com/pihole
But on a more serious note, it is simple products like AdGuard DNS which will probably make Ad-Tech sweat more, because it's so easy to use for average users.
Adblock was compromised due to lack of integrity imho.
I realize it's not performant, but it makes it hard to choose a dns provider when several have different features you like.
To make it easier to install and maintain I used this dockerised version https://hub.docker.com/r/pihole/pihole/
But I can understand how this would frustrate people, especially when they don't know how to disable it or aren't given the password.
To be fair, we're very light/casual web users as most of my hobbies/entertainment are physical electronics and my wife/kids mostly watch Netflix/Stan or just browse reddit/news sites.
I'm sure there's plenty of stuff it breaks (due to how it works and how complex modern sites/web-apps can be), I've just been lucky that all of the sites we use seem to work fine.
Haha, I remember some years back a popular C++ programming site would break if you didn't have an adblocker because someone had put wide header banner ads in both of the side banner areas, shrinking the text to a single word column in the middle. I guess they only tested their website with adblockers on...
Also, there is a popular whitelist project for the Pi-Hole that can make it more user friendly: https://github.com/anudeepND/whitelist
I understand the devotion to a cause but it was too myopic for me.
I definitely do not want to break things for people and I'm happy to remove any reasonable domains from the list. I wouldn't consider google analytics a reasonable one to remove - but you get the idea. I hate to hear you had a bad experience of it. If my list had the breaking domains for you, I would of loved to have a ticket opened where we could discuss it. Sometimes it isn't clear cut between ads & tracking and useful services.
And this story is 100% accurate. I'll try and find it.
You can configure the lists that you use to suit your needs. You can also whitelist any domains that you need. It's up to you what you ultimately block!
It's safest for us, and our reputation, to stay out of the finer points of the actual blocked/not domains and instead defer to individual list maintainers who make that their business.
But I did find a very similar request here with a work around: https://www.reddit.com/r/pihole/comments/49ckht/feature_requ...
So I understand you don't control the lists, but you do control the oobe and it seems like it might not be working for some people.
Oobe is either 1)leave suggested defaults as is 2)don't use those lists.
Option 2 is available in the installer before you're even up and running. There is only so much hand holding we can do, to be fair. We have an extensive support community, and plenty of documentation, and yes, whilst I agree some users may fall between the cracks, the majority are able to find a solution to their problems.
And I did find a solution, just not with you product :)
https://pgl.yoyo.org/as/ has lots of formats.
I live the ability to block SM on my networks. FB can get to be such a distraction with employees.
Even his very benign banner represents an attempt to manipulate. A company buying such a banner wants an author to speak as he wouldn't naturally to give a degree of attention to the sponsors content that he wouldn't naturally inspiring us to give an unnatural degree of regard to the sponsor by implying that he does by plastering it on the top of his website.
He expresses that blocking this attempt at manipulation is "unjust". Hi Troy as soon as your content leaves your website and runs on my computer there is no moral dimension to how I choose to display or not display elements.
In the larger context he believes that the larger struggle is to find a way to fund creators through acceptable manipulation that merely tries to hack your brain but doesn't hack your computer or take up your whole screen.
Maybe when there are a billion people out there blogging and the infrastructure to reach hundreds of thousands costs $20 per month nobody is going to pay you to blog.
Most of the intellectual property out there isn't scarce and you are going to have to convince at least some of your readers that they ought to take the affirmative step of paying you to create because they value your work. If you can't you'll have to pay the $20 a month yourself and create in your spare time.
Acceptable manipulation isn't an avenue I'm interested in supporting.
Incidentally the pi-hole is an interesting but pretty bad solution. It is just technical enough to discourage 90% of people from ever trying it, worthless outside your home network, and requires even those interested to actually pull out their credit card and wait for shipping. This is enough to convince another 99% not to do it. If the website doesn't work with this dns based blocking OR you want to show ads to support that site this is in theory possible but only if you log in to another machine and edit its list over ssh?
Whereas ublock origin can be installed by anyone in seconds for free, works everywhere, and can be selectively disabled on a particular site in 2 clicks. This is why almost nobody uses a home dns server but adblock extensions are becoming prevalent.
Troy also tries to throw shade at extensions by suggesting that any particular extension could be bought by malware authors. This is a legit threat model we should all think more about but it applies to all software including the developers of pi-hole.
"The last temptation is the greatest treason. To do the right deed for the wrong reason." -- T S Eliot
Troy doesn't want us to avoid extensions so we don't get compromised he wants us not to run adblock extensions because they block his source of revenue.
I'd also neved point to Cloudflare resolver 1.1.1.1, and to Google's too. Use your VPN's dns or Quad9 9.9.9.9