Because I wonder what percentage of bandwidth (in terms of bytes) trackers/banners/ads account for.
Need to set up a pi-hole ... just too many other projects....
My pihole is showing 18.7%-23% of requests blocked :)
It would be nice to know how much we're wasting.
Normal display ads all being blocked is generally fine 99% of the time, but if you care about not being permanently tracked across the internet then there are a couple more domains you have to add - except some sites make it mandatory that those invasive fingerprinting scripts and port scanners run and report back a session, otherwise you're refused login or banned.
Is it their content to do what they want with? Sure.
Does the same logic apply to the $9 I used to give them each month? You're damn right.
They focus not only on tracking but also malware prevention, where possible via dns filtering.
Pi-Hole still does not properly support wildcard filtering, only via regex but that is not really efficient (requires tons of resources).
Yes you have to log in to the interface unless you engineer a way around it
Can be nice to use to quickly disable pihole to get through to a particular website.
I can't effectively keep a mental black list of all the sites which I don't want to click on.
Best part? Trying to convince the operators of such sites that users they cannot see in their "analytics solution" are worth fixing their site for is not exactly a straightfoward job - from their narrow view, these users simply do not exist, because the tracking does not show them!
An no, there isn't "tons of alternatives". In theory there is. But in practice, they can really make your life harder. Some may say that Signal is an alternative for WhatsApp, but if people you communicate with don't want to use anything but WhatsApp, then Signal is useless. I hate Facebook but when I want to plan an event, I found nothing better, simply because that's the platform that reaches the most people. Network effects... But also, your favorite show may not be on "alternative" streaming platforms, sometimes your job, or worse, the government may require a specific website.
There are extremists who are ready to find alternative friends, shows or jobs just to avoid using some website. It is a good thing these people exist, that's how progress is made. But for most people you have to make compromises.
Ah! That's why I haven't missed Facebook. I am old enough that I don't plan events any longer.
(Or maybe I have no social life. Actually, that's right, I don't. ;-))
When I need to access ads.google.com or analytics.google.com for my company, I turn on Cloudflare, and pihole is bypassed.
wget --quiet "http://PIHOLE_IP/admin/api.php?disable=60&auth=YOUR_API_TOKE..."
You can find the token in the pihole Web GUI at, Settings > API/Web Interface > Show API token
I'm all for news sites, for example, hoisting ads if I knew they were getting the money from those ads, knew the ads were actually coming from their site.
I wonder if you could hijack those requests at your router and send them back to your Pi-Hole? But then they just switch to DNS over TLS...
In the corporate world, I think the future is managing your network by managing every single device on your network. Only let authorized/corp devices in and all those devices must be enrolled in an MDM solution that enforces all sorts of policy and includes monitoring traffic/DNS queries. Of course that's a lot more work than just monitoring things at the network level.
Your computer sends the raw domain name to pi-hole (e.g. ads.google.com), and pi-hole returns 0.0.0.0 if it's on the block list.
There's nothing Google or anyone can do to make pi-hole stop working.
For now, I've configured my router to force all UDP port 53 traffic to my Pi-Hole which overrides what I mentioned above.
But, in the future we may start to see IoT Devices hard-code DoH servers which will be harder to force over to the Pi-Hole.
Oh wow, how do you do that?
[i] Target: https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
[] Status: Retrieval successful
[i] Received 59896 domains
[i] Target: https://mirror1.malwaredomains.com/files/justdomains
[] Status: Not found
[] List download failed: using previously cached list
[i] Received 26854 domains
[i] Target: https://s3.amazonaws.com/lists.disconnect.me/simple_tracking.txt
[] Status: No changes detected
[i] Received 34 domains
[i] Target: https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt
[] Status: No changes detected
[i] Received 2701 domains
[i] Target: https://dbl.oisd.nl/
[] Status: Retrieval successful
[i] Received 1167690 domains
[i] Target: https://phishing.army/download/phishing_army_blocklist_extended.txt
[] Status: Retrieval successful
[i] Received 21379 domains
[i] Target: https://raw.githubusercontent.com/deathbybandaid/piholeparser/master/Subscribable-Lists/ParsedBlacklists/AakList.txt
[] Status: Retrieval successful
[i] Received 5 domains
[i] Target: https://raw.githubusercontent.com/deathbybandaid/piholeparser/master/Subscribable-Lists/ParsedBlacklists/Prebake-Obtrusive.txt
[] Status: Retrieval successful
[i] Received 3 domains
[i] Target: https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-blocklist.txt
[] Status: Retrieval successful
[i] Received 14724 domains
[i] Target: https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
[] Status: Retrieval successful
[i] Received 412 domains
[i] Target: https://raw.githubusercontent.com/hectorm/hmirror/master/data/adaway.org/list.txt
[] Status: Retrieval successful
[i] Received 9182 domains
[i] Target: https://raw.githubusercontent.com/hectorm/hmirror/master/data/disconnect.me-ad/list.txt
[] Status: Retrieval successful
[i] Received 2701 domains
[i] Target: https://raw.githubusercontent.com/notracking/hosts-blocklists/master/hostnames.txt
[] Status: Retrieval successful
[i] Received 209608 domainshttps://github.com/StevenBlack/hosts
What is the advantage of having DNS on a separate device other than that it provides ad blocking for multiple devices?
But also you can have more flexible block patterns. I run DNSCrypt-Proxy and my block lists can have wildcards. With /etc/hosts you have to enumerate each origin. It can also do things like IP blocking where if any domain resolves to a known ad network IP, then that request is blocked.
But mainly, DNSCrypt-proxy encrypts all my outgoing queries and round robins them across resolvers. (Also hi dheera!)
Kid's computer has dnsmasq as a similar solution.
Obviously not a NextDNS specific issue, it’d happen with anything that blocks the call, but just putting it out there for the next sucker that tries to google why their IKEA gateway suddenly stops responding.