The last bastion left is ublock origin. Please, more people need to move to it (and while at it, consider moving to firefox as well).
The last bastion left is ublock origin. Please, more people need to move to it (and while at it, consider moving to firefox as well).
- hardware, and I’m lazy (admittedly, that doesn’t really qualify as a good reason);
- I browse on mobile, at work, from cafés, etc.
I like the idea of having a device that handles my connection everywhere and my mobile and laptop are always “on wifi” with that device. I’d love to have a centralised solution to use the dodgy wifi connection at airports, for instance.
Here's a dated but reasonable overview of the process from Digital Ocean: https://www.digitalocean.com/community/tutorials/how-to-bloc...
I use a combination of PiHole, Firefox+uBO, and VPN + FW rules to stay as much away from ads as possible even when browsing mobile. uBO is the single most convenient and effective measure out of all of them.
dns.adguard.com [1] is decent for a free offering, though offers no custom rules.
It doesn't have to be real hardware: you can run pihole in a VM (KVM, Hyper-V, etc) on your local machine. It'll eat a bit of RAM of course, but it doesn't need a huge amount to serve one user.
This doesn't solve the setup time of course, and trouble-shooting time if something goes wrong.
For mobile I run OpenVPN at home: all my traffic when on on my phone provider's network or public/guest wifi goes down that including DNS request going to my pihole instance. This isn't perfect of course: there is still some setup and maintenance involved, and some networks block or significantly throttle VPN traffic (throttling can be worked around by running the VPN on port TCP443 if it is done by simple port based rules but that may mean having a spare IPv4 address to hand).
And in my case the VPN is not just for accessing my ad-/malware- blocking DNS resolver, but also for accessing other local resources and for general paranoia (nothing goes over the mobile network or public/guest WiFi unencrypted). Useful extra feature: because payment processors think I'm at home I'm bothered less by extra identity verification steps than I would be if my source address and therefore derived location changed regularly.
DNS traffic going through the VPN stops the network intercepting and forcing it through their resolver anyway (I'm looking at you, Sky) and means that I don't have to make my DNS resolver visible to the unwashed masses.
So I'm not just being obtuse. IMO, anyway.
Pi-Hole (or equivalents, I use the OpenWRT Adblock package on my router) work through domain and host-based blocking, which is powerful, but not exclusive, and carries side-effects. As a bonus, if your local resolver (which is what Pi-Hole is) serves your local LAN or WiFi network, ALL devices are automatically protected, at least while they're on that network (and are configured to use that resolver).
uBlock Origin works based on domain-based blocks, but also other heuristics, and (where the capability exists) can block specific elements within Web pages.
Generally, Pi-Hole or other resolver-based DNS blocklists:
- Covers all local devices and applications.
- Its configuration can be automatically configured via your network's DHCP server.
- It covers all applications.
- It works only for devices while they're using that network or DNS resolver.
Generally uBlock Origin or other extension-based adblockers:
- Cover only the application for which they're installed.
- Offer more extensive blocking capabilities.
- Work regardless of network you're on or when roaming in mobile state.
Where possible, I use both. For devices and apps in which uBlock Origin (or equivalent) isn't available, I rely on DNS-based blockers. When I'm mobile, unfortunately, I get ads, and really, really, really, really hate them.