AdGuard Home: Network-wide ads and trackers blocking DNS server
github.com
github.com
Pihole has many options for different blocks, but all have downsides.
The few apps I use, I haven't experienced time out or crashing issues as a result of PiHole. You might have other network or DNS issues.
Properly not worth it for the task you described. Simply add a DNS whitelist to AdGuard or manually unblock those domains causing issues.
Nothing major but annoying to have to deal with everything being broken because of maintenance or whatever else.
AdGuardHome (and pi-hole) work almost entirely on domain blocklists they regularly download from configurable sources (AdGuardHome also incorporates Google safe browsing). This blocks a lot of stuff, but NextDNS also has options like blocking typo squatting, newly registered domains, domains that are created by domain generation algorithms, and whatever their "AI-driven threat detection" feature is doing. It's hard to tell how useful those features are and there's no reason blocklists couldn't incorporate all those kinds of things. But I have no idea if they do, and outsourcing putting all that together to a service like NextDNS seems like a better solution than a locally hosted option that relies on a user figuring out the right blocklists to use. Although NextDNS also allows you to play with blocklists if you want.
https://github.com/nextdns/nextdns
looks like it proxies standard DNS traffic to NextDNS via DOH, and does some other fancy stuff including caching, zeroconf discovery, and conditional forwarding.
Dang, this looks like a nice option for my home setup - I may give it a try!!
As for simple-adblock vs adblock, I prefer the former because malformed lists won't break DNS, which it does for adblock.
See option 3 in gp's link: apparently theres an Adguard package for openwrt.
My work application has domains that resolve to localhost for our dev setup, and it took me several days to figure out what the issue was. Basically, OpenWRT by default filters out any DNS records that resolve to "local networks" like 192.168.0.0/16 or 10.0.0.0/24. The benefit of this approach is that our services only run with TLS, but you will need whitelist some addresses!
Edit: I found this post on pi hole forums explaining the situation with DoH / DoT. I think this will become a much popular topic to discuss on HN soon as both technologies are increasily popular.
https://discourse.pi-hole.net/t/blocking-dns-over-https-doh/...
Our unlikely allies in making sure in-app adblocking stays possible...
pi-hole was great back in the day but unless you're just keeping on keeping on with an existing install there's better options available now.. AdGuard Home, Blocky, Technitium DNS etc.
I often compare pi-hole to DD-WRT inasmuch as it was awesome back in the day but times have changed and you probably wouldn't use it as first choice these days given what else is now available to you.
If I want metrics, I just open a browser and see what clients have been the noisiest, what’s being blocked a lot and so on. Generally I don’t even think about it.
Encrypted upstream lookups. Responding to encrypted lookups made to themselves. Realtime threat protection via API. Quick toggle of blocks instead of rebuilding lists. Ability to quickly change blocking of individual devices. Decent Metrics.
Probably more.
But if you just want something with no web bling then there's other alternatives to dnsmasq which would be worth looking at which give some of the above features whilst keeping it commandline and manual blocklist building.
dnscrypt-proxy is wonderful, for example, and can do most of the stuff you can do in dnsmasq.
I can easily see what domains are blocked in the web ui and see that Adobe products are trying to phone home so often and which clients are trying to resolve what domains.
AdGuard Home is a lot cleaner to use. In particular it makes it much easier to control routing for queries by domain and supports forwarding over DNS over TLS, DoH, and DoQ natively. SSL support is a breeze. This means that my ISP can see the IP addresses of hosts but not their domain names unless they get aggressive with snooping. The single binary and clean configuration is nice.
PiHole seems to have a better landing page for analytics out of the box. It also works a little better for configuration for some devices.
I’ll likely retire PiHole in favor of AdGuard Home the next time the SD card dies on that Pi.
My preferred configuration is using some fairly invasive scripts to redirect all outbound DNS except to NextDNS. I’ve got blocklists for DoH hosts because I can’t just block port 443. AdGuard then routes to one of two different backends: for local domains it routes to CoreDNS that gets the hosts from my UDM-Pro to give everything nice hostnames. Everything else goes out via DNS over TLS to NextDNS. On PiHole it’s a little more complicated as it can’t directly forward with DNS over TLS.
It’s amazing how many semi-hostile devices this found on my network (looking at you Samsung TV and devices that hard code in Google’s DNS). It also reminds me of how terrible the internet is when I don’t have these protections.
Curious both about load on the raspberry pi and how long it takes browsers to fetch pages
Whereas Pihole... where do I start
pihole was only using steven black list last time i checked.
[0] https://raw.githubusercontent.com/StevenBlack/hosts/master/h...
https://apps.apple.com/app/apple-store/id1543143740?platform...
This looks great. Currently I'm using Hyperweb, which is working great, but one thing I'm missing is an easy way to disable blockers for a particular site - and for it to remember that. As far as I can tell, all I can do is use Safari's 'Turn off Content Blockers' - but this doesn't seem to remember where I did it, and only seems to work temporarily / not for a whole domain, so I end up fighting with it.
It'd be good to block these data collection requests.
Updating pihole is as simple as: pihole -up
Easy enough to cron up.
So, idiosyncratic in that it's not "apt update", but also pretty nice that it's all self-contained.
A lot of projects are also now available as docker containers, so you can just pull down the latest container version, currently my preference for home hosted things.
Of course, but how do you automate this? Using Watchtower? Setup instructions never address this aspect. I get the impression that there’s no standard way to auto-update, and most people only update manually?
The easiest way to keep it up to date is probably a Cron script that runs curl to trigger the upgrade API endpoint.
[1] https://github.com/AdguardTeam/AdGuardHome/blob/master/opena...
[2] https://github.com/AdguardTeam/AdGuardHome#getting-started
I'll admit I briefly switching back to pihole after Russia invaded Ukraine given that AdGuard is a Russian company. Whether or not that was a reasonable choice, the technical step back was obvious and noticeable.
https://github.com/AdguardTeam/AdGuardHome#how-does-adguard-...
Does this mean AdGuard Home can't block CNAME cloaking? I think pihole supports deep cname inspection.
Source: have AdGuard Home running in my network for many years.
Edit: it even has home assistant integration like pihole. I'm going to test it for a few days and see how it performs. So far I have positive impression.
If you can do OpenWRT, you can do this.