System-wide open source ad blocker for Mac, Windows, and Linux
github.com
github.com
Having just posted the app to a couple of small subreddits before sleep and then waking up to being on the front page over here is quite an experience :) I was hoping to make a Show HN post after giving Zen a bit more polish, but I guess here we are.
Thanks for all the constructive feedback. I totally share your concerns about its security and likewise wouldn't use some unverified application trying to install a root CA on my system. For those wanting to audit the certificate generation and installation code, feel free to take a look at certmanager/get.go and certmanager/install_{platformname}.go. It is mostly self-contained and, I hope, easy to understand. The lack of any instructions on how to delete the certificate is an oversight on my part, and I'll be working on this. Regarding the binaries: all of them are built on GitHub's CI. I wish there was a way for users to verify this fact, but to my knowledge, there is no way to do that currently. You can run and build the app yourself using Wails (https://wails.io/docs/gettingstarted/installation). I'll be sure to add more instructions to the repo in the coming days.
As always, any feedback, help, and suggestions are much welcome.
About your comment of security, I think it’s better to make a FAQ file and write it there to clearly explain.
And one suggestion is I hope zen will have function to choose upstream DNS server (can be DoH or DoT server). It will be the best block ads with combo DNS and HTTPS.
I have a network configuration with 2 dnsmasqs, 1 with pi-hole-style hosts block, and 1 without, and most of my devices get the ad-blocking DNS, 1 gets the "unfiltered" DNS.
To do this from the DHCP component of dnsmasq, you can tag MAC addresses and create different configurations (including which DNS they get) for each tag, e.g. https://github.com/imp/dnsmasq/blob/770bce967cfc9967273d0acf...
There's an Android app called flutterhole which can connect to and activate your pihole's 'pause blocking' feature. I have found this to be the easiest way around the scenario the poster above has mentioned. Doesn't help with figuring out PiHole is responsible obviously. HTH.
I personally setup an instance of Homebridge on the device running Pi-Hole, then use HomeKit on my Apple products to turn Pi-Hole on/off as if it were a light bulb.
ISP’s router has unrestricted Wi-Fi access. I run a router behind it with restricted (via pi-hole) access.
All devices connect to the restricted Wi-Fi. Any time I need unrestricted access, I connect to the ISP router Wi-Fi for some time and back to the restricted when done.
Basically Outside World — ISP Device - internal restricted Router (using pi-hole as DNS) - home devices
So, yes, if looking from inside the restricted router would be in front.
They should't. Bypassing policy is malware behaviour.
Funny that they ignore "my" network DNS, not ISP's. (in the name of freedom)
There is a reason to do this btw. The name should say it all. It'll default to cloudflare but they let you specify what you want. The utility? Let's say I'm not an advanced user, what's my DNS look like? Is it DoH? We both know the answer. So defaulting so users' traffic is default DoH sounds like a security improvement. There's also an additional utility. If I take my laptop and move from my home network to another one, I actually don't end up using a different DNS.
You can also use Mullvad's DNS[0], or switch to 1.1.1.2/1.0.0.2 if you want malware protection on Cloudflare's DNS.
Stop making up conspiracies that don't exist. There's enough BS in the world already that we don't need to make ones up to be upset.
[0] https://mullvad.net/en/help/dns-over-https-and-dns-over-tls
I connect to mine over tailscale DNS.
I recommend adding a tray icon that disables it for 60 seconds (super helpful for the odd site that serves something critical from an ads domain… like my bank).
Only downside is apps don’t have to use system DNS and a few mobile ones are wise enough to bypass.
The amount of crap that still comes through when I turn off uBlock -- but am still using PiHole DNS, which is always active on my home network -- is a lot.
Honestly I don't think DNS-based adblocking is really viable, long-term. It's just too easy for advertisers and dirtbag website operators to get around it. There's just no substitute for controlling the retrieval of content elements and their presentation from the application where the user is doing the interaction.
This is why keeping browsers out of the hands of adtech corporations is pretty important; once they control that presentation layer it's largely game over. They can just tunnel all the traffic through a single connection to a relay server, if they want to, and there won't be shit a user can do about it once they've decided that's the only browser they can use.
A proxy can be installed "onto the OS" of a RPi. It does not have to be installed on the computer used to view web pages.
A Pi-Hole is a modified dnsmasq installed "onto the OS" of a RPi.
Being able to MITM any HTTPS request on my system is a privilege I'd not grant lightly. It's up there with browsers, browser extensions (with "all content on all sites" access), and password managers in terms of blast radius in case anything goes wrong.
You don't know this person, and I see no personally identifiable information to make me trust them. They could literally be a state actor right now! We've also seen so many large supply-chain attacks over the last decade which could easily target a tiny project like this.
I agree with the parent - not wise.
Incidentally, no I have no objections against closed source. I find the religious dogma behind FOSS patently stupid.
I mean, no, I would dispute you, because everything Microsoft is doing in those products isn't publicly available for the world to see.
Still probably pretty unlikely because those products are hugely popular and widely scrutinized.
As I said, I think it's still pretty unlikely that Microsoft products are compromised by a state actor. It's certainly not part of my threat model. I'm not sure what point you're trying to make though. I certainly wouldn't install a system-wide HTTP proxy from a developer I didn't trust. And I don't have much of a choice but to trust Microsoft, their products are so ubiquitous I often have little choice.
Of course, you do have a problem as you've already made clear. However, that problem stems from how Microsoft's code is closed source compared to Google's open source code. That's religious FOSS dogma which I referred to earlier, and has nothing to do with whether programmers are paid to write and examine your code.
The hardest part is determining that you want to go through all of this hassle to replicate something browser extensions already do (for the most part).
> All you have to do is view the changes/new commits every time you want to update.
These can be thousands of lines of code per day in busy projects.
I'm installing it now and the best part is if I don't like something I can change it. OSS FTW.
How would you know that for future updates?
I think we have to face the reality that web browsers might no longer be considered "user" agents.
I think too many techies are, much like yourself, contributing to the problem by refusing to move away from Chrome for "reasons"[1], and then compounding it by refusing to acknowledge that "web browsers" != "Google Chrome".
[1] The "reasons" are of dubious quality. Myself and many others are able to do all normal web-browsing from firefox or firefox forks with no functional or performance degradation.
Contrary to your assumptions, I've been quite vocal against the Chrome/Blink monoculture for a while. Unfortunately there is a legit case for it; several generations of "low-end" devices (anything older than 10 years basically), that are still quite capable and in common use, where the difference in performance between Firefox and Chromium becomes quite noticeable, especially as you try to watch video.
I don't think the problem is "techies", we have zero influence outside our own circles - see the historical rates of Linux adoption. The problem is we need the good ol' hammer of antitrust to start swinging again. We also need the regulators to be smart; if we get really unlucky, they will target iOS Safari instead. (This would be good in a healthy ecosystem, but would only serve to further entrench Google's position in the current situation.)
By the way, using a filtering/rewriting proxy has other merits, especially on said older hardware; you can rewrite the entire web page to make it more lightweight and accessible. Check out miniwebproxy[1] and medium-rare[2]. It's also quite simple to write one; you need maybe a hundred lines of Go to start getting results. I've been experimenting with integrating Readability[3][4]; and I think there's more potential to this approach.
[1]: https://humungus.tedunangst.com/r/miniwebproxy
[2]: https://humungus.tedunangst.com/r/medium-rare
I apologise for my incorrect assumptions. What browser are you reading this on, right now?
If by "web browsers" you mean specifically Chrome, yes. Firefox, Brave, and others are all committed to supporting MV2, and will continue to serve my interests as a user for the foreseeable future.
Well obviously, if you keep insisting on using a browser made by Google, an ad company.
Building the code yourself for every update is also a solved problem on every system with a feature complete package manager, including Windows. Trust is not so easily solvable, but if you trust nobody, you can choose to look at ads.
Sorry, I change my question to "how is this a usable free?"
Applies to this program no different than your Linux distro.
Of course there could be other tools that can help verify things such as checksums on reproducible builds.
If none of that is "usable" enough for you, feel free to set up your own tooling and automation
Thank you. That's my point. There is no point in stating that some open source code is somewhat safer because "it can be audited". No. As you said, it's the same as everything I use on my computer. Unless we can establish a consistent safety level for certain type of projects, we can't claim an arbitrary category of software is somehow better.
I don't have any trust in any of those components you mentioned, but I came to terms with the risks associated with using them as part of my threat model. However, I find the notion that open source is somewhat safer because "we can audit it" exaggerating if not misleading. It's not a valid argument, and it should never be used because there's no way to do it in an either practical or consistent way for the users of the said product.
You're not living in a vacuum. The more users (and perhaps more importantly, contributors) an open source product has, the less likely it has intentional backdoors built into it.
There is no way to easily verify that unless some trusted bodies do this for us and publish their work specifically for what you're using.
Now you just have been stating a problem and no solution.
I do agree with you though that "hey it's OSS and easy to verify because we have the code" is indeed lying to ourselves and especially tools with privileges like this (MITM your encrypted traffic) should not be taken that lightly and have the proper warnings, disclaimer and attention (to watch for bad behavior)
Please define "easily"
Software like this has way too many opportunities to exfiltrate information for that approach to work.
https://www.charlesproxy.com/documentation/proxying/ssl-prox...
https://www.charlesproxy.com/documentation/using-charles/ssl...
It made me very curious to find out what data they're downloading / exfiltrating that they feel the need to go to such extremes to hide it from the user.
FWIW, even some of the packages that do pass through MITM are further encrypted binary blobs, not clear text.
Except things like browsers (e.g. Firefox, Chrome) or python that ship their own root CA trust store.
Although I think YouTube et al see an increasing amount of revenue and viewership coming from apps... and if they could, I suspect they would kill their web sites in favor of apps where they have much more control.
Fuck the corporate-authoritarians who are taking away the freedom to do what we want to content that enters our machines. They've been fighting that war for a long time, and we can see through the tactics they've been using.
I've been using Proxomitron as a filtering proxy for over 2 decades after its author's death, and it is even more powerful than this (but requires more setup and tuning.)
That makes deep ad blocking, local web caching, and automated history logging (with paths) impossible, for better or worse.
https://adguard.com/en/adguard-mac/overview.html
There's also Little Snitch Mini:
It's a very different story on mobile, but there, certificate pinning can also trivially bypass this kind of blocking, and for good reason too: Imagine a system-wide tool like this getting access to online banking credentials, for example...
How much better is Mullvad Browser and why?
I am a light user of LibreWolf (I mostly use Iridium browser)
Worse than a browser extension where I can deactivate per-site to solve false positives.
Well, nope.
It isn't as flexible or powerful as other methods, but it is very simple. Tools are all about how you use them. Ignoring them isn't any better than suggesting them.
Still very, very scary.
Every time you stamp it out they find a way to sneak it back in.
I still prefer Windows with ads modified to hide those ads over MacOS though.
If you don't like it, you don't have to use MS products.
My point is the only situations where you have no control over browser installs are when the machine is locked down in such a way that you also cannot install root certificates.
I know back when I did more freelancing with podcast clients this was a constant problem. The OS folks were using could reek havoc if it wasn’t safari, edge, or chrome 90% of the time.
As it happens I lived through this in the early 00s with IE but back then I used Opera for personal browsing and IE for work.
Even in the very remote possibility that you can somehow make changes to root certificates but cannot install a second browser (and I’m being charitable here because there are literally zero reasons that would ever happen), it would still make more sense to update your local hosts files with a pihole-list block list rather than installing your own root cert and using a 3rd party tool to MITM all your web traffic.
I do get the appeal of this tool. I honestly do. But there are so many safer ways to solve this same problem.