HNHacker News
TopNewBestAskShowJobs

lightswitch05

429 karma · joined July 28, 2013

https://www.github.developerdan.com/
submissionscomments
lightswitch05··on 13% of my website visitors block Google Analytics
Thank you for the info, I'm sorry I misrepresented your project. For some reason I thought you had to enable advanced settings.

Thanks for everything you do with uBlock Origin and uBLock Matrix. uBlock Matrix is one my the primary tools I use when researching domains to add to my blocklist.

lightswitch05··on 13% of my website visitors block Google Analytics
So, the domain in question is ms.markosaric.com. Which is a CNAME to custom.plausible.io. uBlock Origin is able to block based on CNAMEs, but it is not a default configuration. PiHole V5 blocks based on CNAME as well, and it is actually enabled by default.

I run a little blocklist project [1] and I've had custom.plausible.io blocked in my list since April 8th [2]. So, although I didn't have ms.markosaric.com blocked directly in my list, the PiHole still would have blocked it via CNAME blocking. Also uBlock origin if you have CNAME blocking enabled.

[1] https://www.github.developerdan.com/hosts/

[2] https://github.com/lightswitch05/hosts/commit/21fd108ffd2996...

lightswitch05··on All-in-One DNS block list
Looks like my lists are intended to be included, but it was linking to the raw Github source instead of the hosted Github pages version. I went through a major refactor 21 days ago that moved my sources lists around a bit - but preserved the links that are supplied all over the README and the Github hosted pages. So, not only is the project linking to the wrong place, but my list has been broken in it for 21 days now without notice.

Its fine that people love creating these massive all-in-one lists. But I recommend just using the sources directly. That way, if a list gives you trouble, you know who to open a ticket with, or just disable that specific list if its too aggressive for your tastes.

My lists: https://www.github.developerdan.com/hosts/

lightswitch05··on Google no longer providing original URL in AMP for image search results
Yes, that is even better! Unfortunately it doesn’t work on iOS, or I would have never created my list. Literally the only thing I miss about Android was being able to use browser extensions like uBlock Origin with Firefox on Android. Safari has its built-in content filters but it’s not the same.
lightswitch05··on Google no longer providing original URL in AMP for image search results
Yes, as you say, Integrity is preserved. However, Confidentiality is also another important aspect of Information Security. Making a 3rd party appear as a 1st party, is a privacy and confidentiality violation, which is why I do not like AMP and signed exchanges.
lightswitch05··on Google no longer providing original URL in AMP for image search results
I'm glad you like it! If you have any issues with it, I encourage people to come open a ticket explaining what is wrong. Sometimes I screw up and block things that shouldn't be - other times I have reasons why I blocked something and the ticket provides a good place to have a that discussion. Feedback from the community is great help to me in improving the lists.
lightswitch05··on Google no longer providing original URL in AMP for image search results
I couldn't agree more that AMP is terrible. I do everything I can to avoid it. Using DuckDuckGo certainly helps, but I will still occasionally stumble on an AMP site. I've created a hosts block list to help me avoid AMP as much as possible. It currently has 3,569 unique domains (works great with a PiHole!). I'm really concerned about Chrome's 'signed exchanges' where they can fake the URL completely. I hope Firefox will never support it.

https://www.github.developerdan.com/hosts/

lightswitch05··on Microsoft buys corp.com so bad guys can’t
I had no idea about that config, but I've seen the behavior before. That behavior is even more interesting considering that Firefox will hide the 'www' subdomain in the URL[1]. So not only will it silently add the www, but it also won't show it in the URL! SMH!

1: https://www.ghacks.net/2020/02/28/firefox-75-address-bar-res...

lightswitch05··on Microsoft buys corp.com so bad guys can’t
That was a fascinating write-up! I too immediately looked for `domain.name` registration and would have marked it up to DNS trickery after that gave a NXDOMAIN. I'm glad you followed the rabbit down the hole on this one. I've added the resolving domains to my Pi-hole block list: https://www.github.developerdan.com/hosts/
lightswitch05··on The opt-out illusion: how we have acquiesced to losing our privacy
Pihole uses a forked version of dnsmasq they named 'Pi-hole FTL engine'. I don't believe there are any features of dnsmasq that cannot be used with the PiHole - but how to configure it to work alongside of PiHole might not be as obvious.
lightswitch05··on The opt-out illusion: how we have acquiesced to losing our privacy
It is resource inefficient, which is why PiHole supports it, but does not allow you to subscribe to list containing regex, as that would quickly make it unusable. I'm not sure how Dnsmasqs would be accomplishing this feature without some sort of pattern matching logic - which would have the same inefficiencies. Basically O(N) where N is the number of domains/patterns that should be blocked. There could certainly be a cache to keep track of matched/unmatched queries, but I would imagine with the modern web the average case would still be very close to O(N). Just speculation.
lightswitch05··on The opt-out illusion: how we have acquiesced to losing our privacy
Pi-Hole does support regex and wildcard based blocking
lightswitch05··on The opt-out illusion: how we have acquiesced to losing our privacy
I maintain a hosts-formatted blacklist for all Facebook owned services, like Facebook and Instagram. Combined with a PiHole, its a fairly effective way to reduce tracking exposure to Facebook. https://www.github.developerdan.com/hosts/
lightswitch05··on The opt-out illusion: how we have acquiesced to losing our privacy
I took a look the domains being used for the consent and saw an interesting JavaScript name: 'messagingWithoutDetection.js'. Looking into it more, I found the documentation [1], there is this disgusting paragraph:

> The Dialogue Javascript communicates with the Sourcepoint messaging server on a subdomain of the site. The benefit of doing that is to allow messaging cookies to be “first party” and thus, circumventing Safari’s web browser Intelligent Tracking Prevention (ITP). This creates a discrete messaging channel between the publisher’s messaging subdomain and the Dialogue messaging server. Once you have created the subdomain, you should create a DNS CNAME record to direct traffic to the Sourcepoint messaging endpoint message<account id>.sp-prod.net where the account id refers to you account ID in the Sourcepoint user interface

Luckily uBlock Origin now supports blocking on CNAME records and PiHole is rolling support out for it as well. I maintain a blocklist that I use with the PiHole: https://www.github.developerdan.com/hosts/

[1] https://documentation.sourcepoint.com/web-implementation/sou...

lightswitch05··on Revoking certain certificates on March 4
> I assume that by default certbot only checks the expiration date of local certificates against the system clock, it doesn't ping any external resources so it can't be aware that the certificate might have been revoked even though it hasn't expired.

I think the actual issue here is that the certificates have not been revoked yet. We know that they will be revoked, which is why we have to run with --force-renewal, but there is no process for certbot to know that a certificate, although not revoked, will soon become revoked. I would expect certbot to automatically renew the next time its ran post-revocation.

lightswitch05··on Should you self-host Google Fonts?
Thanks for sharing! Also `fonts.gstatic.com` is a CNAME alias for `gstaticadssl.l.google.com` which is commonly blocked by ad blockers. uBlock Origin recently added CNAME based blocking, and PiHole is rolling out support for it too. Just another reason to host it yourself.
lightswitch05··on Neat URL cleans URLs, removing parameters such as 'fbclid' and 'utm'
What are your thoughts about it being an open source extension?
lightswitch05··on Neat URL cleans URLs, removing parameters such as 'fbclid' and 'utm'
I've been using this extension for a couple years now. In fact, I submitted the pull request for the fbclid feature [1]. @Smile4ever merged and released the change the next day. It is a really great extension with a responsive and helpful maintainer. I'm glad its getting some more visibility.

Extension Links:

Firefox: https://addons.mozilla.org/en-US/firefox/addon/neat-url/

Chrome: https://chrome.google.com/webstore/detail/neat-url/jchobbjgi...

---

[1] https://github.com/Smile4ever/Neat-URL/pull/163

lightswitch05··on Burnoutindex.org
Ah, I took this quiz on my iPhone, luckily my pihole caught the trackers. I have a pretty extensive hosts list I use with the PiHole (full story included): https://www.github.developerdan.com/hosts/
lightswitch05··on Wacom tablets track every app you open
I don't think anyone would make the argument that a PiHole is a replacement for following best practices in terms of computer and network security. I'm just pointing out that a PiHole can block google analytics and other common violators of privacy. Its not a security tool and isn't advertised as such.
lightswitch05··on Wacom tablets track every app you open
This is just one of many reasons to use StevenBlack's Hosts [1] list to block this type of behavior. While it doesn't currently block link.wacom.com, it would have prevented the subsequent requests google analytics. It works even better when paired with a PiHole [2] to protect all devices on the network.

[1] https://github.com/StevenBlack/hosts

[2] https://pi-hole.net/

lightswitch05··on Show HN: PHP Version Audit – Audit Your PHP Version for Known CVEs and Patches
I wrote PHP Version Audit to automatically keep track of PHP patches, particularly for releases that fix CVEs. This morning it automatically updated to include new CVE patches and releases: 7.4.1, 7.3.13, 7.2.26. This was the test to determine if it was ready for a 1.0.0 release, so its official now. I would love to hear any thoughts on this new tool. Thanks!
lightswitch05··on Pi-Hole 4.3.2
No problem, there is a FAQ on it: https://discourse.pi-hole.net/t/how-do-i-add-additional-bloc...
lightswitch05··on Pi-Hole 4.3.2
I agree that blocking OCSP (Online Certificate Status Protocol) servers is a bad practice. The argument to block them is that they can be used for tracking purposes. OCSP stapling is a great way to use OCSP without the risk of tracking - but not everyone does it or supports it.

Anyways, I maintain an 'Ads & Tracking' blocklist that I believe is pretty reliable and you are welcome to give it a try if you like: https://www.github.developerdan.com/hosts/

I've been maintaining my list publicly for over a year, and I've got to say its not always clear what deserves to be blocked, what should be blocked but can't be due to broken functionality, and what is legitimate like the OCSP servers. Everyone has their own personal level of expected privacy vs functionality. Its impossible to make everyone happy. I just wanted to say that being a maintainer of these lists isn't always easy. The obvious example you provided with (ocsp.apple.com) isn't exactly obvious because it _could_ be used for tracking, and it certainly isn't need for functional reasons (although I would argue that it is needed for security reasons). Anyways, there is a lot of gray when it comes to blocking and you can't make everyone happy.

lightswitch05··on Pi-Hole 4.3.2
If you are looking for more blocklists, I maintain several. I recommend my 'Ads & Tracking' list for most people. I also have an aggressive list - which I don't normally recommend. I also have a Google AMP list and a Facebook products list (not just facebook - but their other products as well). Anyways, you are welcome to check it out and give me any feedback you have:

https://www.github.developerdan.com/hosts/

lightswitch05··on Dear Google, I'm Blocking You from My Website
I also hate AMP and its getting harder and harder to avoid. I created a hosts file that blocks as many AMP domains as I can find. Personally, I would rather not read an article then to visit an AMP site. If you are interested, here is the AMP hosts file: https://www.github.developerdan.com/hosts/lists/amp-hosts-ex...

The hosts file is easily added to something like PiHole, uBlock Origin, or Steven Black's hosts project. Many other tools also accept host formatted block lists.

I'll be the first to admit that the list is lacking, but I would love to accept pull requests if anyone else has an interest in contributing their list of known AMP domains

lightswitch05··on Blocking website ads with a hosts file
You might be interested in this ticket: Encrypted subdomains for routing ads https://github.com/StevenBlack/hosts/issues/801

A PiHole could do wildcard blocking for the subdomain - but as in the ticket where the content for the site is also served from the same encrypted subdomains - nothing can be done. uBlock origin filters also fail at blocking these requests. After some research, I found a potential solution is to block off of request headers, since the ad tool is using headers as a way to send data. Unfortunately I'm unaware of any browser based tool that is able to block requests based on header content.

Its very interesting that this encrypted subdomain tool is only enabled in chrome and not Firefox. It will also detect if the developer tools are open or not. WebMD is a good example where this tool is being used.

lightswitch05··on Parliament seizes cache of Facebook internal papers
I found an article about the ongoing Six4Three case in CA [1]. From the article:

> David Godkin, Six4Three’s lead counsel said: “We believe the public has a right to see the evidence and are confident the evidence clearly demonstrates the truth of our allegations, and much more.”

I have little-to-no legal understanding, but it seems to me that it was in Six4Three's interest to have these documents seized and perhaps released to the public? I see others here talking of how bold of a move this was for Parliament and that it wouldn't have worked if Six4Three simply refused. However, if Six4Three was trying to get the documents released anyways, was this really that bold of a move? Seems to me its more just giving Six4Three an excuse to leak the documents.

1: https://www.theguardian.com/technology/2018/may/24/mark-zuck...

lightswitch05··on Parliament seizes cache of Facebook internal papers
I didn't realize it was an AMP link until I clicked and saw that it had been blocked. I have a growing hosts block list specifically for AMP hosts. If anyone else wishes to block some AMP hosts, here is the link: https://github.com/lightswitch05/hosts/blob/master/amp-hosts...

I don't use Google anymore, so the list only has 362 at the moment, but I keep adding more as I find them. Pull requests are welcome!

lightswitch05··on Invisible Manipulation: ways our data is being used against us
My comment is on the loss of privacy. I am not an aggressive driver and I suspect that I might get a discount if I joined one of these programs, but I value my privacy too much for that. I do not want my every move monitored by my insurance. OnStar would even have the ability to report GPS location. How much longer then until the locations you visit are also factored in- or perhaps that info is used to ‘enrich’ other insurance types. What if your car insurance shared with your health insurance that you visit fast food restaurants twice a week? That’s hypothetical right now, but my point is that the data is so valuable that companies will become more and more invasive to get it- especially insurance. At some point these optional privacy violating practices will become required unless we have legislation protecting us.
← PreviousPage 2 of 3Next →