PiHole-Google: Completely Block Google and Its Services
github.com
github.com
I could imagine shadow-burning YouTubers without banning them by shrinking their recommendation audience.
Further, it would be good for Google. Every little shift in the weather is going to get blamed on them whether they deserve it or not, now that it's common knowledge that they weild this power in more than zero cases. Google is about to discover why judges write opinions. Administering justice from secret meetings leads to popular dissent more than it leads to justice.
Are you sure that it does, and that it's not just a case of "hey we've never seen this person before, but they watched X, let's immediately start with recommendations Y and Z because other people who watched X were engaged with it?"
I’m 39, divorced, and have 2 kids
It’s almost as if the big data sales pitch is an epic joke like nuclear powered everything being pitched in the 50s
So my point was aimed more at advertisers buying on Twitter: they filled in the blanks and got them all wrong. And the one they had the data for they got wrong.
That and I’m not a internet consumer really. Twitter can see I’ve blocked over 1,000 accounts that promoted tweets. Is that statistic being shared with advertisers?
Likely not. Advertisers believe so who cares.
It’s so ephemeral as to be useless.
It means it is the most representative of what would be a common YouTube experience.
There is also this project which is similar but much better, more polished, and with more features than what I have currently, but I haven't tried it to see if it supports a similar kind of selective proxying: https://github.com/omarroth/invidious
Then there's Freetube, which supports proxying but I'm not sure of the details either. It doesn't scrape Youtube itself as far as I know; instead it consults with the main Invidous instance at invidio.us which provides an api: https://github.com/FreeTubeApp/FreeTube
It can get frustrating when it only recommends a single topic. I might go through a phase where I want to see videos about something specific. The recommendation algorithm will re-enforce that and prevent me from moving on to something else. I found that if I make some effort to watch a lot of videos about other topics, they appear. You can also manually edit your viewing history.
1) use Firefox with multi-account containers, and disable 3rd party cookies.
2) put youtube in it's own "youtube" container. do not login to that container
3) put all other google stuff in it's own "google" container
If you do that, and don't login to google except in the "google" container it makes it more difficult for google to know who you are on youtube or other non-google sites.
But to make it so they REALLY don't know who you are, you need to do the above plus use a VPN. In my own usage I've discovered that youtube will recommend you videos based on your IP address's recent views if your not logged in.
Very rarely have any news outlet.
> it makes life bearable in China without a VPN
If you're already a firefox user, you might try the "FoxyProxy Standard" extension to selectively bypass the GFW for the domains you need. Friends in China are reporting a varying degree of success with setting up forwarding on Apache (TLS1.3 with padding). Obvs, don't forget to set authentication. Once you're there you can add your own DoH to the mix.
From: http://www.chromium.org/Home/chromium-security/security-faq#...
"Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. “Data loss prevention” appliances, firewalls, content filters, and malware can use this feature to defeat the protections of key pinning.
We deem this acceptable because the proxy or MITM can only be effective if the client machine has already been configured to trust the proxy’s issuing certificate — that is, the client is already under the control of the person who controls the proxy (e.g. the enterprise’s IT administrator). If the client does not trust the private trust anchor, the proxy’s attempt to mediate the connection will fail as it should."
Can you point to or write up a blog post with a proof of concept?
https://github.com/FiloSottile/mkcert
https://turbofuture.com/internet/Intercepting-HTTPS-Traffic-...
[Edit: Now that I think of it, I’m not sure if Squid is really required...]
Would automatically remap to
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.4.1/jquery.m...
(The corresponding problem with that being how many people would then blame that as browser bloat and complain about the size of all the fonts and how much they "clutter" one's font system.)
The browser would have to be pretty tricksy to solve the tracking problem with local fonts, because the tracking techniques themselves are pretty tricksy.
Such as: Render text to a GL target as fast as possible and hit detect the metrics of the asked for font versus the fallback font.
You would think techniques by the browser to minimize FOUT (flash of unstyled text) mitigates against this sort of tracking, but some of the techniques involve timing between JS load and DOM Ready events.
Admittedly there are easier tests than font loading tests for deanonymization on the web, but obviously if the goal is to de-Google it is worth keeping in mind.
// ==UserScript==
// @name localize ajax googleapis
// @version 1
// @grant none
// @run-at document-start
var scripts = document.getElementsByTagName("script");
for (i=0; i<scripts.length; i++) {
var parent = scripts[i].parentElement;
var url = new URL(scripts[i].src);
if (url.host === "ajax.googleapis.com") {
url.host = "ajax.googleapis.com.local";
var newscript = document.createElement("script");
newscript.type="text/javascript";
newscript.src = url;
parent.insertBefore(newscript, scripts[i]);
parent.removeChild(scripts[i]);
console.log("Rewrote url as " + url);
}
}
// ==/UserScript==
EDIT: I just read the other comments and installed decentraleyes. I'm sure it's way better than this grease I just posted.https://addons.mozilla.org/en-US/firefox/addon/google-contai...
Only problem with it is now reCAPTCHA sites are a huge pain to use since you have to answer about 15 challenges before you can get (since you look totally unknown to Google outside of the container). It is often better to just ignore these sites now, but it is not always possible.
Figure out what domains I need to access for the content I am after[1] and just allow those. "Block" everything else. For example, I might need something like .googlevideo.com once in a while but I will never need something like googletagmanager.net.
1. To do this, I just go through the logs of a local authoritative nameserver that I run solely for this purpose, i.e. collecting lists of needed domains. Then I add the necessary DNS data to /etc/hosts or another local authoritative server, e.g., tinydns. I believe unbound or pdns_recursor can serve static data as well.
Does the author mention avoiding using Google as a third party DNS service. In the beginning, PiHole, i.e., preconfigured dnsmasq, was pointed at some third party DNS service, maybe Google. Not sure what the default configuration is today. If it was Google, then is there any irony in that a project designed to blocks ads is by default having its users send their IP and ISP location to an advertising company probably hundreds if not thousands of times over in a single day of web use.
I tried the whitelisting approach but quickly found out this breaks many websites with shopping cart and credit-card checkouts because they use payments api gateways. Because the url for the card processing gateway is a different company from the ecommerce site you're visiting, it has a totally different spelling so you can't predict what to put in a whitelist beforehand. In turn, if you do whitelist the payment gateway url, you might then find out it makes another api call to a fraud detection url which is another totally different url that you didn't know you had to whitelist.
Whitelisting DNS entries is workable for use inside of a single virtual machine that deliberately restricts a web browser to access a few websites like youtube.
However, I don't see how it's possible to use the whitelisting strategy on a PiHole that globally filters the entire family accessing it with multiple desktops and smartphones. It's not easy to tell if a spinning hourglass or beachball is happening because the a website is slow or whether the whitelist is missing some url entries. The family members would constantly be visiting new and legitimate urls so it seems very cumbersome to try and keep up with adding new whitelist entries for everybody.
However, I rarely use the web for commercial purposes. Almost all use is non-commercial.
I do not use a Pi-Hole. I do like dnsmasq. I prefer djbdns. I use older hardware running Net/OpenBSD as routers and newer hardware running OpenWRT.
I also do not use popular graphical browsers much. I probably would not use whitelisting if I was doing all web use via a popular graphical browser. I reasonably consistent speed across all websites by using text-only browsers and tcp/http clients.
Cannot really speak for other users. Everyone is different. For me, whitelisting works well.
Whenever a necessary site is blocked it only takes a few seconds to whitelist it. I can also easily blacklist sites. The GUI is very easy to access and use. We have never had an issue with YouTube (YT premium) or anything else really, but occasionally a link will be blocked because of Google or other ad traffic. This has never happened with YT or any other streaming services.
One thing to remember is VPN traffic ignores the Pi-Hole server. Even when the router/computer/device DNS is set to use it. This has never been an issue for us, as only a handful of devices here are using VPN, but I suppose it could be under the right circumstances, but easily fixable.
Never seen it listed out like that, I thought it was FAANG. Or is FAANG only used in reference to top salaries in the Bay Area?
> dig TXT +short _netblocks{,2,3}.google.com | tr ' ' '\n' | egrep "(ip4:|ip6:)"
Gives you a full list of all of Google's IP blocks. You can just blackhole those.
whois -h whois.radb.net '!gAS15169'I tried .apple.com, .yahoo.com, etc. and got nothing.
Another method is using GeoIP's ASN database, but they also run many ASNs so it would require a little effort to ensure you have them all
Anything that is blocked is SUPER quick and easy to resolve through the web GUI (but recaptcha has ever been an issue). It seems to be smart enough that I rarely have to access it to unblock anything.
[0] https://gizmodo.com/i-cut-the-big-five-tech-giants-from-my-l...
A way simpler solution is to simply not have a registered account with those companies. That's where the problems start, when they tie certain browsing and telemetry data to your true identity.
For everything else a good content blocker + the typical pihole list that include telemetry domains are enough protection.
I am registered with Apple and Amazon, and there's no way for me to change that because there is simply no one else that delivers this kind of value.
Long-term I could see the possibility of leaving Amazon, but there is a security-advantage when using amazon because otherwise I would leave all my personal data to countless small vendors who regularly get hacked, etc.
Signing up for an account is just more explicitly forking over and sharing data. But you're being tracked by every possible method, and it is possible to piece together the remaining information.
Did you even read my comment? The typical pihole lists already include tracking domains.
What you imply is that if I visit youtube.com with tracking disabled, they still create a profile of me. Then tell me, what unique identifier do they use?
Maybe they have machine learning which combines a couple of factors and then create long-term profiles based on the likelihood of some data belonging to the same person.
That would be illegal though.
It's not really a choice to say "just don't use it", because even appearing on a site with Google tie ins feeds mineable information.
The reason google pushes the log-in in their browser is exactly because they want to be able to tie this all to your account.
Yes, they use randomised hostnames, but there are other parts of the URL that are not.
If you don't want to use a browser extension for pattern matching the whole URL, you're gonna need a transparent proxy in your networks gateway.
Whatever does that mean? Is that a browser thing or a firewall thing or something else entirely?
http://www.routeviews.org/routeviews/
Particularly reverse DNS queries.
The value of these platforms are not technical, they are entirely from the human element and everybody should be able to participate without opening themselves to surveillance and abuse.
Like everything else to run a civilized society we need laws and its unfortunate that this basic first principle of organizing human society needs to be reiterated and debated right untill 2019 because of propaganda by Koch brothers and their ilk on a self serving libertarianism which is as fantastic as a disneyland version of reality.