Googling this, development ended in 2004? An informed summary of the current state of play would be interesting, since a lot of different "continuations" of it seem to be around. Also, is it Windows-only? (I've been casually looking for a simple proxy that would enable injection of local links into remote content.)
The readme goes on to say: "Privaxy is also way more capable than DNS-based blockers as it is able to operate directly on URLs and to inject resources into web pages."
Can’t Wine help with this?
What works are browser based ad-blockers and app patchers like ReVanced. As my savings have gone up, I've relied more and more on just paying for ad-free services like YouTube Premium, Hulu, Netfix, and Max for the cases those 2 can't handle.
Because they're often ads made to look like search results. Pi-hole working as intended.
That's my experience anyway. My family network is behind a pi-hole and rarely if ever does an intended website visit break as a result.
It works really well and is simple to manage. It runs on my mobile devices easily.
I turn it off occasionally to shop, but immediately turn it back on as the internet is a whole different place without some sort of robust ad blocking.
It’s nice to see the logs fill up with blocked telemetry and other crap all day.
I use a layered approach. I’ve been using Pi-hole for 8-10 years, don’t remember, with about 1-2M in the block list.
In addition, I use uBlock as well as pfsense with pfBlocker-NG for blocking countries and other features.
They all work well together. Sometimes I have to bypass them, when I momentarily use the ISP’s Wi-Fi router directly.
It’s been working fine.
Since Cloudflare employees are known to lurk here, I'd like to know: is this considered a false positive, or working as intended?
Greetings from a country whose (almost) entire IP space is blacklisted by Cloudflare!
greetings from the other side of the world, commandline brother. I did not know of this tool, but I do now. Thanks
> Software engineer from Belgrade, Serbia
"Regimes" sounds pejorative but in truth, companies have a duty and in many cases a legal obligation to protect their networks. Prima facie, I don't see any reason at all why interception of traffic in this circumstance is "bad," except maybe a potential for political misuse like any other written medium.
I actually think the reverse would be substantially worse: if _only_ the public trust chain was valid in major browsers, we would be completely hosed and there would be no distinguishing factor at all between remote attestation and trust.
Thus, corporate TLS interception is, at worst, a necessary byproduct of a very well chosen tradeoff.
> The term "Cyber Monday" was coined by Ellen Davis, and was first used within the ecommerce community during the 2005 holiday season. According to Scott Silverman, the head of Shop.org, the term was coined based on 2004 research showing "one of the biggest online shopping days of the year" was the Monday after Thanksgiving (12th-biggest day historically). Retailers also noted the most significant shopping period was December 5 through 15 of the previous year. In late November 2005, The New York Times reported: "The name Cyber Monday grew out of the observation that millions of otherwise productive working Americans, fresh off a Thanksgiving weekend of window shopping, were returning to high-speed Internet connections at work Monday and buying what they liked." At the time, a lot of people had slow Internet at home. The idea for having such a holiday was created by Tony Valado, in 2003 while working at 1800Flowers.com, and coined "White Wednesday" to be the day before Thanksgiving for online retailers.
Sounds like something that would be "trivial" to defeat, by means of "emulating" other TLS implementations more closely?
Regular http gets redirected to proxy, non-standard traffic needs to be explicitly allowed out.
what else do you MITM for?
Once the requests leave the computer and travel onto the internet destined for another computer, then of course "MITM" makes sense as a concept. We all want to prevent that.
The computer owner controls the proxy and it's the proxy, not the untrusted application, like a "modern" web browser for example, that handles authentication of the remote peer. Compiling and fully controlling a "modern" browser is a PITA. Almost no one does it, even software developers. Instead people beg for an advertising company or their partner to make changes to a browser. That does not seem to work. Sometimes when people complain it stops the company from making undesired changes. But only temporarily.
Whereas compiling a proxy is easy and the user can fully control it.
Having used many different applications that implement support for TLS, I actually trust the proxy's implementation more than most applications. It's arguably easier to audit one program, the proxy, than it is to check every application to make sure the developer didn't make a mistake when adding TLS support. I recall socat as one example. That mistake went undetected for a long time. Elinks was another. At the time, it was dropped from OpenBSD ports as a result.
[1] https://reshade.me/forum/troubleshooting/8746-reshade-v-5-8-...
www.digitalocean.com
arstechnica.com (Amazon)
git.kernel.org
cdn.netbsd.org (Fastly)