I've toyed with the idea of setting up a no-FAANG VPN that implements these restrictions based on the ip networks advertised by the relevant ASNs. This would provide more complete coverage, and be useful as a testing tool, allowing you to verify that your own web properties still function without assets being loaded from a global active adversary.