So, while I use an adblock list with my unbound caching DNS server, it only works with devices which honor the local network DNS settings, which are becoming fewer and fewer thanks to the efforts of the major players to _HELP_ everyone with DOH. A protocol without an easy way to MITM/filter the requests even when the user wants it.
I co-develop a FOSS DNS + Firewall for Android that prevents apps from doing their own DNS over HTTPS / TLS / QUIC by blocking all connections to IPs that the DNS client (embed within the firewall) hasn't resolved itself or the TTL of whatever answer it once resolved has expired. Something similar to this could and should be implemented by other firewalls, too. The result of such a blanket setting is devastating though, as some apps (like Telegram) refuse to do plain-old DNS and hence refuse to connect at all (so, one may have to selectively allowlist certain IPs / apps). This also has a happy side-effect (or annoying side-effect, depending on how one looks at it) of breaking apps connecting to static IP endpoints (ex: Orbot connecting to Tor bridges).
Plus (getting back to the topic at hand), having adblock for all your devices is so ... pleasant. You forgot how jarring and upsetting (and LOUD) advertisements are. Having them puncture your DNS adblock while using Chromecast is like getting a wet slap in the face.
I expect there are probably umpteen different ways to block ads with a little digging, although I can't vouch for any as I don't have a Chromecast (or TV) myself.
FWIW, a while back I reached my eye-twitch limit with Raid: Shadow Legends (deeply impressioning irritating ads: ...why...?), and so I stared at YouTube's load process to try and figure out if I could viably block everything.
The technique I ended up using exploited the fact I was running within a Chrome extension and overloaded JSON.parse (lmao), and was specific to the HTML delivered for desktop, but has worked for months.
I reckon it's quite possible the data sent to Chromecasts is similar enough that you could viably block it by MITMing the device then rewriting the JSON (or possibly gRPC) responses being sent to it.
Using YouTube Vanced on a no-name Android TV stick might be an alternative. (Untested but should presumably/theoretically work.)
I think it's currently this:
https://raw.githubusercontent.com/StevenBlack/hosts/master/h...
I run my own resolver (unbound) that I point all of my networks/devices to.
That resolver has, as its upstream, my nextdns.io account address. nextdns has the pihole/ublock lists built-in.
So you get to run your own DNS server, you don't have to implement any of the blocking yourself, and you just point your upstream to the address you get when you sign up.
I'm quite happy with this setup ...
Only a matter of time before applications begin to roll their own encrypted forms of DNS in order to circumvent ad blockers.
DNS filtering and blocking is a very powerful tool great for bypassing many features/pitfalls of the internet.
I do this; no machine other than my 2 DNS servers are permitted to make outbound DNS requests (they are transparently handled by my LAN DNS).
The real annoying change is the transition to DNS over HTTPS. The canary domain[1] is useful but apps are obviously free to ignore it.
[1]: https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
I've seen it as high as 73%.
This won't prevent OPs concern with apps doing DNS over HTTPS, would it?
> No way to bypass the DNS at that point via the firewall.
Some apps do not even do DNS and connect to static IPv4s and IPv6s straight-away. Even if IPv4 is limited, plenty IPv6 to go around than an ip-table can handle.