Pi-hole: Network-wide ad blocking
github.com
github.com
As for the pi-hole setup itself, it's working great. It's a great backup to locally installed adblockers, and I have my EdgeRouter as the primary DHCP DNS server, which makes requests to pi-hole. Both the router and pi-hole have caching, and my DNS query latencies are good. Pi-hole also has a nice interface for pointing `.local` domains to local IP addresses, which is much easier than messing with dnsmasq settings on the EdgeRouter.
https://news.ycombinator.com/item?id=31707222
tl;dr: If the TV is working well enough already, it may be ill-advised to connect it to the network. The apps, while convenient, can be supplanted by an external AppleTV or similar for minimal cost relative to a nice TV. This protects the TV not only from being a privacy threat and general ad-ridden nuisance, but also from receiving potentially harmful updates that can lead to performance regressions.
This is why I have Pi-hole set up as well. I wanted to have custom DNS records so I can resolve multiple named services to the single IP they're hosted on. With my Ubiquiti Security Gateway you have to do this by SSHing in and modifying the dnsmasq settings. It's much easier for me to manage this on Pi-hole. The DNS request metrics and blocking are just a bonus for me.
The problem is, for anyone who wants a smart TV, every brand is just as bad. Samsung, Sony etc.
I know some people say "get a dumb TV" and use chromecast etc - but I just want an all in one integration etc.
One thing I've been feeling lately with internet-connected home devices is that I'm being pushed towards products from big tech companies like Google. Google might mine my data still, but at least they'll ostensibly do it competently and securely. Not a great feeling. Despite not really being in the Google ecosystem, maybe my next TV will be one with Android TV support. On the smart home side, I did get into self-hosting Home Assistant recently. I didn't expect much from it at first, but it's remarkable how liberating and useful it feels compared to the one-size-fits-all approach of Google Home or HomeKit. I'm actually excited to try and get some more smart home devices now, beyond just a few lightbulbs.
Google knows everything about you/us if you use their services. It's really bad, we know. For some of us that's inescapable because of our careers/jobs, or if we use Google search on our own devices on our networks compared to alternative platforms. Even your smart lightbulbs are gathering data on you. Android (AND Android TV) is Google:
> https://arstechnica.com/gadgets/2021/03/android-sends-20x-mo...
Something like "Absorbent nature they have for information" if you still want to use absorbent.
100% would not buy another LG TV.
I believe this company still sells them.
We let users block connections to IPs that have no corresponding DNS request. Of course, genuine reasons to connect directly to IPs exist, but not so much for installed apps.
The other one is to use the web browser more (since the likes of Firefox have super effective content blockers baked in) and not install apps.
My only problem now is that android seems to only allow a single VPN 'tunnel'/connection, so I can't -so far as I know- simultaneously use your app with a dedicated VPN service like Mullvad. Is there any easy-ish way to get around that?
In my searching around, at least one person has suggested using something like insular/Island with all installed apps, then use the 'VPN' service on the non-insular side, but that to me seems to leave open all the 'system apps'.
I don't actually expect that you'd help some rando with this, but it's super cool to encounter a maker of an app that I love, so I thought I would ask on the off chance.
> I just found your app a few weeks ago...
Curious: From reddit, or hacker news?
> I can't -so far as I know- simultaneously use your app with a dedicated VPN service like Mullvad.
If your VPN app supports on-device SOCKS5 proxy, then that's one way to chain Rethink (check Settings) to it. Rethink, for example, can chain up to Orbot (Tor as a proxy over on-device SOCKS5) just fine.
> Is there any easy-ish way to get around that?
If not, wait until we release WireGuard integration. It has been complete for a good part of 5 months now, but we never built a UI for it and now in the meantime upstream impl we rely on (both gVisor/netstack and WireGuard) has changed, and we need to pick those changes up. Expect it to happen in a month or two, along with the UI bits.
1. have separate vlan (named vspy ;) for all the external devices like appletv etc
2. all traffic to internet dns ports (53, 853 etc) is completely blocked from this vlan
3. all trafic to ips list (using ipset matching for speed) containing manually curated few dozens of publicly known DoH servers (including 8.8.8.8 et. al) is completely blocked from this vlan
In other words: use my own dns server or go away.
all services works fine (apple,google, tv/movies streaming etc.) while being in this vlan, and I see "my" devices continuously hit the 2&3 bariers.
My setup is similar (hairpin NAT for DNS to rewrite UDP 53 to my own server, seperate VLAN), but I also have squid set up (whitelist only) with TLS bumping, and have installed my root CA on the TV. The ipset method is good thinking, but you're playing cat and mouse.
Encrypted DNS is more of the same.
Asus Merlin firmware handles this nicely.
Works great.
I have a RaspPi working wonders but I suspect some devices have hardcoded connections which bypass the DNS request. Is there a simple way to forward to that RaspPi for correct “gate keeping”?
I had issues with just DNAT following some ui forum posts, and I think it's because I'm using switch0 as the interface, with devices across LAN ports on my EdgeRouter. The SNAT masquerade was the key to getting the replies from the pi-hole routed properly.
I was previously using my EdgeRouter as the DHCP DNS server, and using DNS Forwarding on switch0 w/ dnsmasq to forward queries to the pi-hole. With a large cache, this avoided a couple hops for every DNS query on my network. However, this meant that I couldn't see which IP was making the query in the pi-hole query logs, so I've flipped it so that the pi-hole is the DHCP DNS server, and the pi-hole queries the EdgeRouter, which then forwards the requests to public DNS w/ caching. I then assigned every device a '.local' domain in the pi-hole Local DNS tab, which lets pi-hole displays a friendly name for each query in the log.
For completeness sake, here's everything I needed on the EdgeRouter. The EdgeRouter was setup with no VLANs, and with all LAN ports switched w/ a single subnet (switch0 interface exists in the dashboard).
EdgeRouter:
* In the bottom left "System" pop up drawer, set "System domain-name" to "local" (or whatever domain of your choice, like "lan" or "home").
* Services > DHCP Server > [Your DHCP Server] > View Details: Set DNS1 to your pi-hole IP (make sure it's statically mapped!), set Domain to "local"
* Firewall/NAT > NAT: Follow above guide
* Services > DNS: Enable DNS Forwarding for switch0, set appropriate cache size
* Config Tree > service > dns > forwarding: set name server to public DNS server of your choicse
Pi-hole:
* Settings > DNS: Disable all external DNS servers, set custom upstream DNS server to the EdgeRouter
* Local DNS > DNS Records: Look at your EdgeRouter DHCP lease list, give everything you care about a static IP assignment, and then give them ".local" DNS records in pi-hole. SSH-ing in and editing `/etc/pihole/custom.list` may be faster, as pi-hole seems to bring services down and then back up for each entry added via the web UI.
Eventually, yes, device/software manufacturers will start using encrypted solutions, but until then, ya do what ya can do. Maybe the blocking solutions will evolve and adapt as well.
I have a nice script that does the same on an edgerouter, some variation on ‘if port 53 and not from Pihole, send to Pihole’.
I'd argue the TV is one of the most harmful inventions of the modern age.
Sitting for hours a day is the new smoking. And the ever more hyper-partisan news rots the mind. All so you can watch the latest trite bollocks Disney et al. has just put out.
Lets not even get started on how they're all streaming services now. So much content yet a fraction of the quality.
I got rid of my TV when I saw a man being gruesomely killed on BBC news ~2014. It was without a doubt the smartest decision I ever made.
A Faraday cage home seems like it would be simple enough to build and fully proof you from such idiocy forever.
that's worked for me... so far..
The analogy is Tesla is the only one making good electric cars. When there's competition, I will never buy Tesla because of the shitty experience.
Also for >$1k it should let you use the TV as an HDMI multiviewer. It has 4 HDMI ports on the back, let me view plug in my personal laptop on the port 1, work laptop on port 2, and divide the screen to give each laptop a "2nd monitor". Or even 2 monitors each.
You mean for advertising, showing timetables, etc?
Those are usually "digital signage" panels. Colors may or may not be OK on those, but there are two things to keep in mind:
1. They are outrageously expensive because they're made to be run blindingly bright 24/7.
2. They are less and less dumb, complete with ridiculously long startup times.
The company I work for uses these. And while a few years ago only the higher-priced ones used to feature "smart" features, the "cheaper" ones now have them, too. Now, in our case, we like those because it allows us to control the screens from a central location, and they don't require setting up a Raspberry Pi or similar to show content on them. But "dumb" they are not anymore.
They're typically running some form of Android or Samsung's Tizen. I don't directly use them, so I don't know the details, but a quick glance at Samsung's website seems to show that consumer models use Tizen, too.
So I think it's just in the WebOS, which I don't really ever use.
In other words, you can use it as a stupid panel and not get ads.
I'm pretty sure the smart features were put into TVs so they could become the one entertainment device just like those external set top boxes in the early 2000's. All consumer media hardware is headed in this direction of having advertisements, even in paid/subscription services. I base this on the fact that Foxtel (effectively the one and only paid TV service in Australia) has more ads per hour than free to air TV as people that pay a subscription are considered to have a higher income than ones that don't.
Which would completely kill the reason to buy it. I highly doubt that Apple is going to do that.
This almost guarantees that at lesson one person is working on it, without a strong customer focused leadership it’s hard to say no to that amount of money.
Maps has sent me to cornfields a few too many times to be trustworthy. It’s incredibly annoying that they refuse to let me choose google maps to open an address. Anti-trust needs to step in some day.
I was able to resolve the wifi issue by resetting the region to another and back and turning off the auto setting for it, but frankly it’s appalling an update can go out that breaks something as basic as Ethernet.
The fact a premium TV shows ads is appalling. Does LG really need to sacrifice their brand reputation just to get that advertising revenue? Whoever is calling the shots for this decision should be fired.
Money can buy reputation, so as long as the revenue from ads exceeds the cost to repair reputational damage, this will continue.
This is also a case where the manufacturer takes advantage of the unstable software Zeitgeist to gaslight users into thinking this is just how things are now, it's normal and natural and if you don't like it you're old/disruptive/weird.
Is it a security hole? Probably. I have it siloed away from my network on its own router with its own subnet.
LG 43UN700-B
I remember looking all over for an "hdmi quadviewer" that had all of these things:
>= 120hz hdr / 10-bit color edid web admin to adjust layouts (or some other method)
I got close, but the biggest thing I can't find is higher framerate viewers. My TV should do this.
-Jack Sparrow, LG CEO
Perhaps this will put to rest the idea that internet-based tracking and advertising are necessary for products and services to be "free" and paying for these products and services is a way to "remove the ads". Even paying a high premium to a company that privacy washes^1 its products will not stop the data collection and advertising.
Some companies can survive without using the internet to violate privacy for profit. Anyone born before 1993 knows this is true. Certainly a company like LG could survive, however "tech" companies cannot.^2 Conducting commercial surveillance on internet users is too easy. It's like money on the table. There is still inadequate regulation to slow it down, let alone stop it. Companies that connect their products to the internet can cash in on "tech" company intermediary-style surveillance. Welcome to the "Internet of Things".
Being able to control DNS in the home is essential, IMHO. Hopefully Pi-Hole users are not pointing dnsmasq at shared caches run by entities engaged in data collection for commercial purposes and internet advertising services, whether those are ISPs or Google or similar.
1.
https://www.context.news/surveillance/opinion/user-beware-pr...
https://dt.gl/privacy-washing-do-as-i-say-not-as-i-do/
https://dataethics.eu/privacy-washing/
https://medium.com/discernible/communicators-steer-clear-of-...
https://getsession.org/blog/privacy-washing
2.
The now classic "tech" company meme is that the internet, what other folks would call the web, would not exist without advertising. Yet it did exist before advertising was permitted, so that cannot be true. It still worked and no one using it wanted to see advertising. The person who put the first ad on the internet was globally lambasted.^3 Citing this historical fact does not imply anyone wants to go back in time to the early internet. It just means that the "tech" company meme that the internet does not work without advertising, without "tech" company intermediaries conducting extensive surveillance on every internet user to support this advertising, is pure BS. "Tech" companies try to use FUD something like, "If anyone changes anything that interferes with advertising, then the internet and therefore life itself will suck." Yeah, right.
As if "tech" companies are the only sources of vision for the future. They want a future that continues to let them profit obscenely from using the internet for unregulated data collection and advertising.
3.
https://web.archive.org/web/20080919130455/http://www.l-ware...
I wonder if that's actually some kind of EU/UK regulation that's absent in the US that's preventing this.
I've overall been very happy with our LG TV and have been recommending it highly over our old Samsung - which was slowly updated to remove features and eventually took about 45 seconds to boot up.
Edit: found this on GitHub https://gist.github.com/wassname/78eeaaad299dc4cddd04e372f20...
ngfts.lge.com
us.ad.lgsmartad.com
lgad.cjpowercast.com
us.info.lgsmartad.com
aic.recommend.lgtvcommon.com
aic.homeprv.lgtvcommon.com
aid.rdl.lgtvcommon.com
aic.lgshopsvc.lgappstv.com
^aic.*lg.*
us.emp.lgsmartplatform.com
snu.lge.com
us.lgrecommends.lgappstv.com
api.thetake.com
us.lgtvsdp.com
aic.service.lgtvcommon.com
lgtvonline.lge.com
(\.|^)gracenote\.com$
(\.|^)prehook\.com$
raw.vidyard.com
(\.|^)vidyard\.com$
(\.|^)wistia\.com$It's listed on https://firebog.net/
Thankfully, it’s almost unpossible to buy a telescreen without telemetry (and always has been), so Big Brother will know what you are doing. But you should still stop by the local MiniLuv for reeducation, just in case.
Are you sure about that? I'm pretty sure I recall being able t&%@^0158
NNNNNNNN@*^&
NO CARRIER
It should be illegal to make money selling a TV and data mining people without their informed consent.
> but the TV was absolutely packed with ads via the home screen and pop-up toasts. To add insult to injury, the home screen would lag for several seconds at boot while it pulled down all those ads.
I was shocked to read this. I've been running AdGuard Home for awhile now and had no idea that my TV was capable of showing me so many ads. Even my spouse breathed a sigh of relief (and possibly admired my setup just a little!) when I read her these lines.
The Roku remote controls TV power and soundbar volume just fine. CEC didn't seem to work quite right, so I enabled the Roku's IR blaster feature. The LG remote can control the Roku as well, through CEC.
I used to have an EdgeRouter which was a huge improvement to the ISP-provided crappy box but ultimately the configuration was so complicated and inconsistent that I switched to a small fanless debian box. I put Pi-Hole there, which also covered DHCP and DNS services (synchronized together).
It has been a blast and I have more confidence that I will understand what is happening (vs the ER magic)
i also have an oled tv from lg and haven’t seen any ads on the home screen but did get 1-2 pop-ups about a year ago. but that’s about it. it’s a 4 year old model, running a webos version that can’t be updated to the latest one. i also bought it in europe.
does anyone know if what the poster describes happens based on continent/country, or webos version? it seems so strange to have such a great panel, pretty much the best OS, and relatively high prices just to spoil it all with ads worth pennies.
As an aside, can you share the additional domains you added to PiHole please.
I am using them sparingly though, and I live in EU, if that makes any difference.
It would make me furious to find ads in software that I've already paid for. Hopefully when I need to replace this TV there will still be options.
Pi-hole seems a more elaborate and powerful approach though.
What? I don't believe you. Are you saying if you are using it as a PC monitor it would effectively send data back about apps you're using, games you're playing, etc? this would have incredible privacy violation implications.
That said, good luck finding something better. Most smart TVs run Android garbage that gets progressively worse as updates fome out, and no dumb TVs (in my country) have the feature set of the big boys. I can't find anything better than LG, even with the absurd lengths I have to go to make it suit my needs.
Most companies have an "about us" section with info where at least you can see who the people/management are.
Instead, they provide a vague page: https://adguard.com/en/contacts.html
I also think for DNS blocking you're best off just adding one list and being done with it. Adding lots and lots of lists only opens you up to more fault positives and problems down the line IMHO.
I’m currently happily using https://nextdns.io/ but I don’t thing you can install that on a Raspberry Pi.
What I hate the most it's how the try to scam no savvy tech people, like grandparents and for those scenarios pi hole it's a tool made in heaven (specially as there are not global adblocks extensions for mobile devices)
I still don't use for my personal network, but for my senior family members that use tech only for video streaming or reading the news, this it's an amazing gift.
Yeah a lot of sites (articles) there's an ad between every paragraph or they scroll you to the bottom which has those garbage sites as you try to leave.
Oh, that's my utter bane. My mom knows better, I've taught her how the manipulations work, and then she'll show me a pertinent article on her tablet, and see an utterly outrageous clickbait link from Outbrain or Taboola or the like, like "This mom found out her kids were smoking WHAT?!" and pictures of some bugs or whatever.
And she'll get a guilty and tortured expression and say "Oh, I know they're probably manipulating me, but I have to find out what this is about." No!!! You really don't have to!
I tried to sneakily install ublock, but I made ONE mistake when trying to add a custom filter on a site she regularly visits, which broke her user experience for 3 minutes before I fixed it, and she demanded I immediately uninstall the "hacker programs".
Viewers see less ads, but probably wouldn’t resort to ad blockers if they only saw one ad on a website instead of 10. Advertisers would get better click through rates because you aren’t competing with as many ads. The downside is advertisers have a higher CPM, and maybe the data shows high CPM campaigns don’t work.
Regardless, after working in it for awhile I see how we got where we are. I don’t foresee a world with no ads since the vast majority of people don’t want to subscribe to every website they visit, but maybe there will be a better model in the future.
https://www.lloydatkinson.net/posts/2022/consider-disabling-...
One crucial thing I use my pihole for is to forward traffic going to the .lan top level domain to my reverse proxy (traefik), I couldn't figure out how to do this in the pihole UI so I just added a custom config file to /etc/dnsmasq.d which works perfectly.
I'm not sure what adguard uses but would be interested to here if it's possible!
EDIT: just seen it supports DNS rewrites, which seems to do a similar job. Nice! I might give this a shot for a while
For example, one of the them is a music database website. Its ad shows the links to buy the CDs (it's in Japan, FWIW). I find it very continent; I often just go Amazon to check info even if I don't want to buy.
Not all routers have this functionality and if it doesn't you should be able to flash Tomato or similar, or use PfSense. Depending how home baked you want to go.
Edit: and her iPhone changes its MAC address randomly so the access control was tricky to maintain.
Not sure it can be done on android.
it's also telling me that a lot of tech products are not tested with women customers at all.
It was actually a pretty tricky bit of technology to build, as it had to work not only for the original link, but all of the associated trackers which were triggered by the event (otherwise the ad might not load).
The developers made a great release awhile back that allowed you to make custom groups of users with their own whitelists. I created a group that whitelisted all google shopping links and then put her in it. Works flawlessly
docker pull pihole/pihole:latest
docker run -d \
--name pihole \
--restart=unless-stopped \
-p 192.168.1.1:53:53/tcp \
-p 192.168.1.1:53:53/udp \
-p 80:80 \
-e TZ="Australia/Perth" \
-e PIHOLE_DNS_="1.1.1.1\;1.0.0.1" \
-e WEBPASSWORD="{redacted}" \
-e DNSMASQ_LISTENING=all \
pihole/pihole:latesthttps://adguard-dns.io/en/public-dns.html#addresses
Also ublock-origin works on Firefox mobile.
Sadly the cat and mouse game between ad vendors and systems like this is, the DNS sinkholing method is either being circumvented thanks to rapidly changing/randomised hostnames outpacing the adlist authors, or ads are rendered server side.
I've never been able to get it to work as the primary DNS source on the router though, so I always have to configure my devices to statically point to the IP of the pihole, but that's just a minor inconvienience (although annoying when devices like TVs don't allow you to configure DNS, or override it secretly for their own stuff)
I have not needed an ad-blocker for the past 2 years and hardly see any websites breaking. Often syndicate links break, which is not a big deal for me.
Aside from it just working, their mobile client is a fantastic thing. When I am off wifi, my phone routes DNS to NextDNS and I get the same adblocking when I am on cellular data.
As one ex, not me but some may be uncomfortable with their use of BigCloud (AWS/GCP/Cloudflare) infrastructure.
I do this on a symmetrical 500Mbit fiber line, YMMV.
So I uninstalled it and went with adguard, which doesn't arbitrarily stop working.
The free(!) plan includes 300,000 queries per month. That is transparent everywhere. On the website, pricing page and in the dashboard. You can even see how much you have already used. That's pretty fair for a free service for which you pay nothing. For me, that's enough for a whole month.
> (..) which doesn't arbitrarily stop working
1. NextDNS sends an email before the limit is reached
2. Once the limit is reached, no more ads are blocked, but dns continues to work
You are using a consumable (CPU & data transfer, along with your desired amount of analytics data storage) that they pay for, and, shockingly, they are not ad supported.
I gave pihole a shot but an update went wrong and I had to muck around getting it to work again (it was also my dhcp, so was a pain whilst working from home!)
Back to nextdns and it’s smooth. I have different profiles set up - a home one (for everything that can’t take DoH, including my work laptop), one for my son (his iPad), one for my wife (no logging, minimal ad blocking, allowing Facebook) and one for my devices (lots of different blockers).
It also works outside of my network too.
I pay the £17/year as I feel allo of this is worth supporting.
Edit: I just discovered this is a thing “Settings > Rewrite”
I had a Samsung smart TV but got rid of it last year because of the ads, slow start up, bad sound, and just all-round bad anti-user crapware that was on it. Reverted back to my old (10 year old) dumb Samsung and it's much better hooked up to a streaming stick.
I long for the days when all you had to consider when getting a new TV was color, resolution, picture quality, frame rate, etc. Instead of what OS it's running, how long you'll get update, how bad the advertisings going to be, as well as the above.
Any recommendations for a decent projector?
Look for DLP projectors if you want watch primally films. They can adjust frequency to FPS of played media and colour reproduction is more pleasant to watch. Avoid LCD projectors. They are great for presentations and graphic in bright environment, not for film reproduction in dark room.
I lived with a projector only for a good decade, when I had no kids and very few hobbies outside of TV/Movies/Games. It was amazing to have a 120" screen with a pretty minimal investment. Fully darkened room and two proper recliners for me and the SO. Great stuff.
Then we had kids. And when the rugrats want to watch Pocoyo or Octonauts or whatever is in fashion at the time, then having the projector on seems just wrong. Never mind that you can't see crap if you have the lights on at the same time.
Yes, you can get modern projectors that have amazing brightness and short-throw projectors that can just be put on a table. But still a 60-70" 4k HDR TV is more practical unless you have a separate theater room.
via https://v.firebog.net/hosts/lists.php which also describes 'Whitelisting Suggestions'.
Alternative: https://github.com/jacklul/pihole-updatelists
It certainly DOES let through a few more trackers, but that's the cost of a list that doesn't cause problems.
Use a better block list (OISD has been mentioned already), or use NextDNS. Neither of those cause breaks in most sites and stop the most bothersome/prevalent ads.
Asus Merlin firmware handles this nicely.
The only downside of the XT12 is that there are no USB ports, so you cannot have external storage. Definitely WTF, but an OK trade-off for me.
My work systems bypass everything and I route them to Quad9. If that breaks my work stuff, then the IT department has some splainin to do.
I am not bothered on the TV. I bought a ~15YO Panasonic Viera TH-46PZ80E, a huge plasma thing that is almost totally dumb. It cost me £/$ 60 a year ago, and it's great. It talks to a cable TV box and an elderly Mac mini for playing videos. Works a treat, costs very little, and zero online advertising.
I have got Kodi on it and our phones for a "ten foot UI", but using macOS is easy enough that we never need it.
TrueNAS Core is a FreeBSD distro. Docker is a Linux tool. That implies to me I'd need a Linux distro in a VM, then Docker on that, then more config on top.
Which sounds hard.
Which is why people run this stuff on dedicated small cheap computers.
I predicted containers were the next big thing 3 years before Docker was founded, but I do not run containers on production servers. My job is writing about this stuff, not running servers. :-)
I write about it because I used to run servers in production for a living, and I didn't like doing it. I prefer writing.
I am not inclined to remove a tool that's working pretty well and replace it with something entirely different just to get access to this one small function. I think that's reasonable, isn't it?
I mean, even if I did, I think Scale is likely to be less efficient on my servers, maxed out at 8GB RAM, and there still isn't a plug-in for PiHole for Scale, is there?
See e.g. here: https://github.com/AdguardTeam/AdGuardHome#known-limitations
Some of y’all seem to enjoy bringing work home and tinkering and maintaining hardware at home - but some of us don’t
I’ll keep my ad blocking on my router thank you very much
Now, if Pi-hole or similar suddenly becomes mainstream, that'd be a different story.
I mainly use pihole for ease of setting up and its user interface. I’m using knot-resolver for upstream queries and knot for local zones.
I’ve started to read up on dnstap to see if I can emulate some of the pihole statistics but pihole is still good enough.
So many sites are basically unusable without it.