A forward proxy is one way. This can be compiled from source and hence completely controlled by the user. One way to set this up is to route DNS traffic to one computer where where the user controls DNS and HTTP, including HTTP headers such as cookies. All HTTP traffic then sent to this computer and it is managed by the proxy. This works really well for me.
With ad blockers and application firewalls (Snitch, Rat, whatever), one must install them on every computer.
If an ad blocker is a browser extension, then it only works for the web browser not other applications. The browser vendor, usually an advertising-supported company, has ultimate say on whether the extension will work or not.
If the ad blocker extension is managed by a third party and it auto-updates, then one must trust that party and make sure that the extension is not sold out to an adtech-related or other "tech" operation looking to profit from data collection and advertising services.
These ad blocker extensions have potentially full access to every page a user views in the browser. The privacy risk does not get any worse. Vigilance is essential.