Currently it's just dnsmasq with a huge blacklist, and I guess it doesn't support checking the whole CNAME chain against that list, which would be really cool.
The browser API used by uBO returns the last CNAME in the chain. I consider the DNS lookup itself to be an non-issue overhead-wise in uBO because:
- The browser would need to do it anyways
- DNS lookup results are cached at both the browser and uBO level
That doesn't help if dnsmasq only checks the incoming request against the list, and not the whole cname chain of the result.
>While this is considered bad practice for a website to set cookies as accessible to all subdomains (i.e., *.website.com), many do this.
>In that case, those cookies are automatically sent to the cloaked third-party tracker.
That is a distinction without difference. The security implication is storing any data with website.com!