System-level ad-blocking in Android
kevinboone.me
kevinboone.me
I use a DNS registrar and certificate that support wildcards. That way, I don't have to leak my DoT subdomain and I gain some obfuscation. Android's Private DNS option doesn't support alternate ports, so I'm forced to use the default.
I use nginx as my reverse proxy and TLS terminator. At this stage, I apply rate limiting and subdomain filtering.
Then nginx forwards the streams to Unbound, which filters out any local IPs from the responses to avoid leaks.
Finally, Unbound forwards requests to my Pi-hole, where the magic happens.
My biggest issue is I can't use it while I'm connected to Tailscale, but my plan is to install AdGuard Home on my homelab and have that take over instead. It does remove many of the functions, but it's better than the alternative
If you're in stock isp land like me (for now, wip), be sure to cover all your bases, because they quietly hand you over to ipv6 if you just have 4 set. Can verify with eg. resolvectl query doubleclick.net
But yeah definitely do it at device level too. For me on android, simple as settings>private DNS>put ipv4
So if I'm supposed to pay for ad blocking, I might as well read the article and use one of the other methods[1] instead :)
[1] I was trying Rethink several times, but WG Tunnel with ad-- and tracker-blocking service works best for me.
I ended up just switching to Control D's free tier using the Hagezi blocklist. You can try Normal, Pro & Pro+ for typical usage (I stick to pro normally). That + Brave and I'm pretty much ad free.
HaGeZi recently launched their own public DNS-over-HTTPS / DNS-over-TLS resolvers: https://github.com/hagezi/dns-servers.
# privacy
root.hagezi.org
# security
ctif.hagezi.orgThis was all pretty simple to setup given hardware that supports VPN, DDNS, etc.
Worth noting too that just blocking hostnames is not enough; Netflix, as an example, uses Google's DNS servers (plain UDP) on some/most clients.
If the network the client operates on can't prevent DNS to other servers, that's a simple "bypass" vector.
AFAIK, the best you can get, given sufficient time, patience, and hardware is:
• something like the above
• blocking outbound DOT (853), DOQ (784, IIRC) excepting, perhaps, upstreams you trust
• blocking HTTPS to known DOH endpoints (Cloudflare, Google, etc)
• DNAT for plain DNS cases like the Netflix example above. (to your DNS server(s))
Even that there's plenty of hypothetical opportunities for clients to just use another DOH resolver outside of your domain/IP block lists.
I also have a VPS setup in a similar fashion in case my home connection fails for one of many reasons.
I try to only practice safe internet. Raw-dog the internet and you're asking for an infection.
I wonder how old it is and what their motivation is/was. Maybe to offer something comparable to Apple Private Browsing?
I'd expect mentioning of the good old Xposed framework.
And then add lists.
And add your own constantly when they miss
I find it naive to state this when earlier he noted that he's suspicious of free services without a clear funding model.
Sure, open source is certainly better than closed source, but its not like somehow magically it prevents exploitation. There's plenty of examples especially in a small project like this with few eyeballs. So why question the funding model of a free VPN but not question the funding model of an open source project? We just assume its being done out of good will? I find that perspective naive.
In Android you can either set your DNS server in the system settings or via the VPN API.
Sample code here https://github.com/t895/DNSNet/blob/a-couple-updates/service...
They both do the same thing. There are local device-only resolver apps like
https://github.com/m66b/netguard
Another famous one is DNS66 but it's sadly unmaintained. Avoid apps with the word "ad" in their name, they are usually semi commercial and can't be trusted.
Do note all of these methods can be overridden on the app level e.g. a lot of browsers come bundled with first party VPNs or use their own built-in resolvers.
If you want something more reliable, Firefox on Android with the UBlock Origin and Sponsorblock extensions is still the gold standard. Though do note the Android Firefox is extremely slow compared to the Chromium based browsers.
For app level ads, use an app patcher like https://github.com/morpheapp which can remove all in-app advertisements and inject sponsor blocking code.
I also prefer replacing uBlock Origin with Ad Nauseum which is built on top of ubo.
Sounds like you're describing Firefox from around the time my phone was made (which was indeed slow and janky, and had lots of UI issues).
Amazon's `ref` parameter isn't used for affiliate codes. It's certainly used for something, but given that internal links have it (eg. the logo in the top left has `/ref=nav_logo`), I wouldn't immediately conclude it's an affiliate link just because it has ref. Actual affiliate links are through the `tag` parameter.
What evidence supports the link referenced being an advertisement? I'm not seeing any referral, tracking, or any URI parameter data at all that would support the claim, and this seems to be their only instance of referring to it — where, in this 'state of the union' helpdesk-style article, one or more such 'VPN provider' links seems particularly relevant to visitors. (I do not use whatever this company's products are and have no opinion either way on them aside from mistrusting the claim presented here.)