Thanks for everything you do with uBlock Origin and uBLock Matrix. uBlock Matrix is one my the primary tools I use when researching domains to add to my blocklist.
429 karma · joined July 28, 2013
Thanks for everything you do with uBlock Origin and uBLock Matrix. uBlock Matrix is one my the primary tools I use when researching domains to add to my blocklist.
I run a little blocklist project [1] and I've had custom.plausible.io blocked in my list since April 8th [2]. So, although I didn't have ms.markosaric.com blocked directly in my list, the PiHole still would have blocked it via CNAME blocking. Also uBlock origin if you have CNAME blocking enabled.
[1] https://www.github.developerdan.com/hosts/
[2] https://github.com/lightswitch05/hosts/commit/21fd108ffd2996...
Its fine that people love creating these massive all-in-one lists. But I recommend just using the sources directly. That way, if a list gives you trouble, you know who to open a ticket with, or just disable that specific list if its too aggressive for your tastes.
1: https://www.ghacks.net/2020/02/28/firefox-75-address-bar-res...
> The Dialogue Javascript communicates with the Sourcepoint messaging server on a subdomain of the site. The benefit of doing that is to allow messaging cookies to be “first party” and thus, circumventing Safari’s web browser Intelligent Tracking Prevention (ITP). This creates a discrete messaging channel between the publisher’s messaging subdomain and the Dialogue messaging server. Once you have created the subdomain, you should create a DNS CNAME record to direct traffic to the Sourcepoint messaging endpoint message<account id>.sp-prod.net where the account id refers to you account ID in the Sourcepoint user interface
Luckily uBlock Origin now supports blocking on CNAME records and PiHole is rolling support out for it as well. I maintain a blocklist that I use with the PiHole: https://www.github.developerdan.com/hosts/
[1] https://documentation.sourcepoint.com/web-implementation/sou...
I think the actual issue here is that the certificates have not been revoked yet. We know that they will be revoked, which is why we have to run with --force-renewal, but there is no process for certbot to know that a certificate, although not revoked, will soon become revoked. I would expect certbot to automatically renew the next time its ran post-revocation.
Extension Links:
Firefox: https://addons.mozilla.org/en-US/firefox/addon/neat-url/
Chrome: https://chrome.google.com/webstore/detail/neat-url/jchobbjgi...
---
Anyways, I maintain an 'Ads & Tracking' blocklist that I believe is pretty reliable and you are welcome to give it a try if you like: https://www.github.developerdan.com/hosts/
I've been maintaining my list publicly for over a year, and I've got to say its not always clear what deserves to be blocked, what should be blocked but can't be due to broken functionality, and what is legitimate like the OCSP servers. Everyone has their own personal level of expected privacy vs functionality. Its impossible to make everyone happy. I just wanted to say that being a maintainer of these lists isn't always easy. The obvious example you provided with (ocsp.apple.com) isn't exactly obvious because it _could_ be used for tracking, and it certainly isn't need for functional reasons (although I would argue that it is needed for security reasons). Anyways, there is a lot of gray when it comes to blocking and you can't make everyone happy.
The hosts file is easily added to something like PiHole, uBlock Origin, or Steven Black's hosts project. Many other tools also accept host formatted block lists.
I'll be the first to admit that the list is lacking, but I would love to accept pull requests if anyone else has an interest in contributing their list of known AMP domains
A PiHole could do wildcard blocking for the subdomain - but as in the ticket where the content for the site is also served from the same encrypted subdomains - nothing can be done. uBlock origin filters also fail at blocking these requests. After some research, I found a potential solution is to block off of request headers, since the ad tool is using headers as a way to send data. Unfortunately I'm unaware of any browser based tool that is able to block requests based on header content.
Its very interesting that this encrypted subdomain tool is only enabled in chrome and not Firefox. It will also detect if the developer tools are open or not. WebMD is a good example where this tool is being used.
> David Godkin, Six4Three’s lead counsel said: “We believe the public has a right to see the evidence and are confident the evidence clearly demonstrates the truth of our allegations, and much more.”
I have little-to-no legal understanding, but it seems to me that it was in Six4Three's interest to have these documents seized and perhaps released to the public? I see others here talking of how bold of a move this was for Parliament and that it wouldn't have worked if Six4Three simply refused. However, if Six4Three was trying to get the documents released anyways, was this really that bold of a move? Seems to me its more just giving Six4Three an excuse to leak the documents.
1: https://www.theguardian.com/technology/2018/may/24/mark-zuck...
I don't use Google anymore, so the list only has 362 at the moment, but I keep adding more as I find them. Pull requests are welcome!